¡¡ Problem, website with badware !!

(based on Google)

BRIEF EXTRACT: Review iframe as caution measure. Additional secure policy detected. No SSL version info. Many metadata extracted. Old Wordpress, please consider updating. Infrastructure of some of the big-players. Website built with Wordpress....

How to proceed, and if you are interested, how does it might be happened



WEBSITE'S REPORT

(assesment based on the following unmasked details):



Web Site

http://www.elplural.com

Let us know if the web site is OFFICIAL WEB NO OFFICIAL o FAKE (sitio con badware)
Awareness value: 70 (with 20 or higher a website is considered somehow security awareness)
ScamAdviser: If you want another opinion, go to ScamAdviser
URL's MD5: a84d3e1cf1b79e31363ab171f5533000
Unmasked on: Oct. 1, 2014, 11:07 p.m.
Domain registered on: ENOM, INC.
Domain will expire in: 09-may-2015 (220 days)
Web server: : cloudflare-nginx
mail.elplural.com = mail.elplural.com has address 185.154.160.198
webmail.elplural.com = webmail.elplural.com has address 172.67.73.196 webmail.elplural.com has address 104.26.6.166 webmail.elplural.com has address 104.26.7.166
ftp.elplural.com = ftp.elplural.com has address 46.16.56.229
forum.elplural.com =
direct.elplural.com =
cpanel.elplural.com =
blog.elplural.com =

(Read more)
Technology: : No data
Robots file:
# www.google.com/support/webmasters/bin/answer.py?hl=en&answer=156449

User-Agent: *

sitemap: https://www.elplural.com/uploads/feeds/google_sitemap_es.xml
sitemap: https://www.elplural.com/uploads/feeds/feed_elplural_es_videos.xml

Disallow: *?idComment=*
Disallow: /buscador.html*
Disallow: /_call*
Disallow: /registro.html
Disallow: /perfil.html
Disallow: /alta-newsletter.html
Disallow: /politica/pelotazo-en-madrid-un-macrocentro-comercial-al-modico-precio-de-60-000-euros-anuales_32143102
Disallow: /opinion/los-calvitos
HTTP methods: Not found
Directory listing: Not found
Third party content: Not found
Electronic commerce: Payment gateway or Paypal or own BBDD (Read more)
Private IPs: No
Iframes:
http://atemda.com/nojsadserving.ashx?wId=230211&pId=456484&rank=2&clk=[URL-encoded external clicktracking link goes here]
-http://widgets.helpmycash.com/std-mejores-productos/?bg=ffffff&header_text=FF1500&tab_bg=F1F4F5&tab_link=FF1500&tab_active_bg=ffffff&pid=45
-http://atemda.com/nojsadserving.ashx?wId=230211&pId=456484&rank=1&clk=[URL-encoded external clicktracking link goes here]
-//www.facebook.com/plugins/likebox.php?href=https%3A%2F%2Fwww.facebook.com%2Fpages%2FEl-Plural%2F129839407046505%3Ffref%3Dts&width=300&height=290&colorscheme=light&show_faces=true&header=true&stream=false&show_border=true&appId=858231750871032
Scripts:
[<script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=25");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', "//]]&gt;--&gt;</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=12");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', "//]]&gt;--&gt;</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=24");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', "//]]&gt;--&gt;</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=22");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', "//]]&gt;--&gt;</script>, <script type="text/javascript">\r\n", '\r\n', " var ADM_PL = {tp:'sp', wId:230211, pId:456484, rank:2, width:120, height:600, pbId:173, clk:'[External click-tracking goes here (NOT URL-encoded)]'};\r\n", '\r\n', '</script>, <script type="text/javascript">\r\n', '// &lt;![CDATA[\r\n', '\tvar vvqflashvars = {};\r\n', '\tvar vvqparams = { wmode: "opaque", allowfullscreen: "true", allowscriptaccess: "always" };\r\n', '\tvar vvqattributes = {};\r\n', '\tvar vvqexpressinstall = "/wp-content/plugins/vipers-video-quicktags/resources/expressinstall.swf";\r\n', '// ]]&gt;\r\n', '</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=26");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', " //]]&gt;--&gt;</script>, <script type="text/javascript">\r\n', '\r\n', ' var _gaq = _gaq || [];\r\n', " _gaq.push(['_setAccount', 'UA-476888-1']);\r\n", " _gaq.push(['_trackPageview']);\r\n", '\r\n', ' (function() {\r\n', " var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;\r\n", " ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';\r\n", " var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);\r\n", ' })();\r\n', '\r\n', '</script>, <script src="//secure-uk.imrworldwide.com/v60.js" type="text/javascript">\r\n', '</script>, <script type="text/javascript" src="http://es.ads.justpremium.com/adserve/js.php?zone=1685"></script>, <script type="text/javascript" src="/wp-content/plugins/tabber-widget/js/jquery.idTabs.min.js?ver=3.2.1"></script>, <script>\r\n', ' var _comscore = _comscore || [];\r\n', ' _comscore.push({ c1: "2", c2: "15068590" });\r\n', ' (function() {\r\n', ' var s = document.createElement("script"), el = document.getElementsByTagName("script")[0]; s.async = true;\r\n', ' s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js";\r\n', ' el.parentNode.insertBefore(s, el);\r\n', ' })();\r\n', '</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\n", ' var m3_r = Math.floor(Math.random()*99999999999);\n', " if (!document.MAX_used) document.MAX_used = ',';\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\n', ' document.write ("?zoneid=21");\n', " document.write ('&amp;cb=' + m3_r);\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\n", ' document.write ("&amp;loc=" + escape(window.location));\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\n', " //]]&gt;--&gt;</script>, <script type="text/javascript">\r\n', ' var _gaq = _gaq || [];\r\n', " _gaq.push(['_setAccount', 'UA-476888-1']);\r\n", " _gaq.push(['_trackPageview']);\r\n", ' (function() {\r\n', " var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;\r\n", " ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';\r\n", " var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);\r\n", '\r\n', ' })();\r\n', '</script>, <script type="text/javascript" src="http://s.atemda.com/Admeta.js"></script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\n", ' var m3_r = Math.floor(Math.random()*99999999999);\n', " if (!document.MAX_used) document.MAX_used = ',';\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\n', ' document.write ("?zoneid=17");\n', " document.write ('&amp;cb=' + m3_r);\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\n", ' document.write ("&amp;loc=" + escape(window.location));\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\n', " //]]&gt;--&gt;</script>, <script>\r\n', ' (function() {\r\n', " var cx = '016744783834944430751:usxgtyxuu_8';\r\n", " var gcse = document.createElement('script'); gcse.type = 'text/javascript'; gcse.async = true;\r\n", " gcse.src = (document.location.protocol == 'https:' ? 'https:' : 'http:') +\r\n", " '//www.google.es/cse/cse.js?cx=' + cx;\r\n", " var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(gcse, s);\r\n", ' })();\r\n', '</script>, <script type="text/javascript">&lt;!--//&lt;![CDATA[\r\n", " var m3_u = (location.protocol=='https:'?'https://ads.elplural.com/www/delivery/ajs.php':'http://ads.elplural.com/www/delivery/ajs.php');\r\n", ' var m3_r = Math.floor(Math.random()*99999999999);\r\n', " if (!document.MAX_used) document.MAX_used = ',';\r\n", ' document.write ("&lt;scr"+"ipt type=\'text/javascript\' src=\'"+m3_u);\r\n', ' document.write ("?zoneid=23");\r\n', " document.write ('&amp;cb=' + m3_r);\r\n", ' if (document.MAX_used != \',\') document.write ("&amp;exclude=" + document.MAX_used);\r\n', " document.write (document.charset ? '&amp;charset='+document.charset : (document.characterSet ? '&amp;charset='+document.characterSet : ''));\r\n", ' document.write ("&amp;loc=" + escape(window.location));\r\n', ' if (document.referrer) document.write ("&amp;referer=" + escape(document.referrer));\r\n', ' if (document.context) document.write ("&amp;context=" + escape(document.context));\r\n', ' if (document.mmm_fo) document.write ("&amp;mmm_fo=1");\r\n', ' document.write ("\'&gt;&lt;\\/scr"+"ipt&gt;");\r\n', "//]]&gt;--&gt;</script>, <script type="text/javascript" src="http://www.elplural.com/wp-includes/js/jquery/jquery.js?ver=1.8.3"></script>, <script type="text/javascript">\r\n', '\r\n', ' $(window).load(function () {$("#BannerPlaceHolder_EPPlayerTV_300").append(\'&lt;iframe width="300" height="505" style="border:0;" scrolling="no" marginheight="0" marginwidth="0" src="http://video.microcontenidos.com/EPPlayerTV.aspx?iframeid=miQ57y8447"&gt;&lt;/iframe&gt;\'); });\r\n', '\r\n', '</script>, <script>\r\n', '(adsbygoogle = window.adsbygoogle || []).push({});\r\n', '</script>, <script type="text/javascript" src="http://www.elplural.com/wp-content/plugins/tabber-widget/js/jquery.idTabs.min.js?ver=3.5"></script>, <script data-mrf-url-to="t.elplural.com" src="http://t.elplural.com/statics/marfeel/gardatenant.js"></script>, <script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script>, <script type="text/javascript" src="http://www.elplural.com/wp-content/plugins/wp-polls/polls-js.js?ver=2.63"></script>, <script type="text/javascript" src="http://s.atemda.com/Admeta.js"></script>, <script type="text/javascript">\n", '/* &lt;![CDATA[ */\n', 'var pollsL10n = {"ajax_url":"http:\\/\\/www.elplural.com\\/wp-admin\\/admin-ajax.php","text_wait":"Your last request is still being processed. Please wait a while ...","text_valid":"Por favor, seleccione una respuesta de la encuesta.","text_multiple":"Maximum number of choices allowed: ","show_loading":"1","show_fading":"1"};\n', '/* ]]&gt; */\n', '</script>, <script type="text/javascript">\r\n', ' var pvar = { cid: "es-elplural", content: "0", server: "secure-uk" };\r\n', ' var trac = nol_t(pvar);\r\n', ' trac.record().post();\r\n', '</script>, <script async="async" src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>, <script type="text/javascript">\r\n', '// &lt;![CDATA[\r\n', '\tvar vvqflashvars = {};\r\n', '\tvar vvqparams = { wmode: "opaque", allowfullscreen: "true", allowscriptaccess: "always" };\r\n', '\tvar vvqattributes = {};\r\n', '\tvar vvqexpressinstall = "http://www.elplural.com/wp-content/plugins/vipers-video-quicktags/resources/expressinstall.swf";\r\n', '// ]]&gt;\r\n', '</script>, <script type="text/javascript">\r\n", '\r\n', " var ADM_PL = {tp:'sp', wId:230211, pId:456484, rank:1, width:120, height:600, pbId:173, clk:'[External click-tracking goes here (NOT URL-encoded)]'};\r\n", '\r\n', '</script>, <script type="text/javascript" src="/wp-content/themes/elplural/js/cookies.js"></script>, <script type="text/javascript" src="http://www.elplural.com/wp-content/plugins/five-star-rating/assets/js/five-star-rating.min.js?ver=0.1"></script>]
Suspicious code: Not found
incrusted spam: Not found
Location: Not found
Google check: malware Warning provided by Google
Metadata: ['http://www.elplural.com [200] Cookies[__cfduid
Metadata: ' Frame, Google-Webmaster-Verify[7XvBEj6Tw9dyXjHST/9sgRGxGymxFdHIZsM6Ob/xo5E=
Metadata: ' HTML5, HTTPServer[cloudflare-nginx
Metadata: ' HttpOnly[__cfduid
Metadata: ' IP[104.28.24.114
Metadata: ' JQuery[1.8.3
Metadata: ' MetaGenerator[WordPress 3.2.1,WordPress 3.5
Metadata: ' Script[text/javascript
Metadata: ' Title[ Peri\xc3\xb3dico digital progresista
Metadata: ' UncommonHeaders[cf-ray
Metadata: ' WordPress[3.2.1,3.5
Metadata: ' X-Cache[plural,plural:80
Metadata: ' X-UA-Compatible[IE=edge
Metadata: ' cloudflare\n']

"If you need help to solve the badware problem in your website , do not hesitate in contact with me

Legend
Details in this colour are: just information (doesn't feed the security awareness assesment)
Details in this colour are: Information collected to asses the security awareness level
Details in this colour are: Information collected to asses the security awareness level

Desenmascara.me. 2024