Website is flagged as Compromised Site by Google
-
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]netWe have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.
-
@Alex-Montarev We actually have a Drupal site and we're having the same issue...
-
Hello
Thanks for the heads-up. We'll look into it immediately and take the necessary steps to resolve the issue.
-
Update: I have also raised this on Google community: https://support.google.com/google-ads/thread/280600750?hl=vi&sjid=17667827560611966802-AP
and one of the member, who claims to be an IT engineer and security researcher, replied that the issue is caused by the library polyfill. The person said that a popular library got compromised and resulted in many site affected by this attack.
We are checking on this and if it is possible, you all can also take a look at this on your sides as well.
Hope this helps.
-
@Pedropeit thank you for the information and the offer to help. I really appreciate it!
Our website provider have tried to scan our website using these tools: Sucuri SiteCheck, VirusTotal, Quttera but we haven't found any unsual things.
We are trying to do a deeper scan at the moment but we are leaning on the possibility that this is a false alarm from Google. If so, do you know how we can reach out to more relevant personnel from Google to ask about this issue other than the general support team?
Thank you!
-
@Alex-Montarev we do not use Shopify, unfortunately. We are still in process of solving this.
We reached out to Google Ads support but only get some generic answers. Have you able to solve it already?
-
Hello there.
I see that in your website, you are using https://polyfill.io/v3/polyfill.min.js?features=IntersectionObserver%2CIntersectionObserverEntry . You will need to remove it as it is a compromised CDN, and it can make your website run arbitrary code. -
@ManpowerVietnam said in Website is flagged as Compromised Site by Google:
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]net
We have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.I understand the frustration you're experiencing with the Google Ads suspension due to a "Compromised Site" issue. Here are some steps and tools you can use to deeply scan your website and address this problem:
Manual Inspection:
Check Source Code: Manually inspect the source code of the affected page for any references to the malicious links (googie-anaiytics[.]com, vty68[.]net). These might be hidden in scripts or embedded in iframes.
Browser Developer Tools: Use browser developer tools (F12) to inspect the network activity on the affected page. Look for any unexpected network requests to the malicious domains.
Online Security Scanners:Sucuri SiteCheck: This free tool scans your website for malware, blacklisting status, injected spam, and defacements. You can access it here.
VirusTotal: Submit the URL of the affected page to VirusTotal to get a report from multiple antivirus engines. You can use it here.
Quttera: This tool provides a detailed report on any suspicious content or malware on your website. Try it here.
Web Security Plugins:Wordfence (for WordPress): If your website is running on WordPress, install Wordfence Security. It provides comprehensive scanning and firewall protection.
MalCare (for WordPress): Another WordPress security plugin that offers malware scanning and removal.
Server-Side Scanning:ClamAV: If you have access to your server, you can run ClamAV, an open-source antivirus engine, to scan your web directories for malware.
Maldet (Linux Malware Detect): This tool can be used on Linux servers to find and quarantine malware.
Professional Help:If the issue persists, consider hiring a professional web security service or a cybersecurity expert to perform an in-depth analysis and cleanup.
Once you've performed a thorough scan and cleanup, you should:Submit a Review Request: Inform Google Ads support that you've taken steps to clean your site and request a review.
Monitor Regularly: Set up regular scans and monitoring to prevent future compromises.
If anyone in the community has faced a similar issue or has additional tools and tips to share, your input would be greatly appreciated.Please let me know if you need any further assistance or specific information. I'm here to help.
Best regards,
-
We're having the same issue with our Shopify store, starting a few days ago. Google says the same thing, this "googie anaiytics" link that does not exist on our site.
Are you using Shopify? I'm wondering if it's a common Shopify app that's hacked or something that's causing this issue.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Keyword & negative keyword overlap
So I just read your blog on quality score and after reading the negative keyword section I'm a little confused and I need clarification. In that paragraph you mentioned about not overlapping your negative keywords with your active keywords and you used an example of dog food and dog bed. So my question is, if you put the word dog bed into the negative keyword list isn't the word dog the over lap word? Would you ad not show because the word dog is in the active keyword list?
Paid Search Marketing | | Vallerinspects0 -
Unsolved Google Ads Not Getting Clicks or Impressions
I have been running some google ads - in the past 7 days I've had no clicks or impressions is this common? #ads
Paid Search Marketing | | PermaTherm0 -
What are the best advertising platforms for B2C?
Recently, Google ads stop being as effective. Same ads, cost, and web pages, but not getting the same results. Our budget is $4500/mo and need to get at least $25,000 in sales before increasing the budget. What ad platforms have you had success with?
Paid Search Marketing | | seotools4me0 -
Is there a way to track visitors that watched my video on YouTube and became a direct visitor to my website after the fact?
I am trying to understand the impact my commercials are having on website beyond just the clicks I get from YouTube as a referring site. Google is telling me there is not a way to track users that have viewed a video. I am trying to think outside of the box to figure out a way to use the remarketing cookie to my advantage. Google says there is not a way to track a user that watched a video and then eventually came to my site. But at the same time the "Earned Views" metric is similar to what I am trying to accomplish. As per Google, "An earned view occurs when someone who views your video ad and then watches another video or videos in a linked YouTube channel within 7 days of the ad view." So I want to be able to apply this same method to people that view my video ad and then surface on my website eventually. Please let me know your thoughts on this and if there is a way to accomplish this goal. Thank you
Paid Search Marketing | | JoeyPasq0 -
How to track in Google Analytics 2 different subdomains (one for website, the other for PPC landing pages)
Hello Mozers! I have a website with organic visits/goals on www.site.com and a few AdWords Campaign landing pages on lp.site.com whose goals are tracked with both adwords conversion monitoring AND analytics (not imported from analytics into Adword). The landing pages of the campaign have nothing to do with the web site (different cms, they don't link each other, totally isolated) and viceversa. Given that, what would it be the best practice to configure Google Analytics to track the website (www.site.com) AND a PPC campagin (lp.site.com)? I have been told to set up different views of the same property, but do I really need that? Please let me know what are you thinking. Thank you very much. DoMiSoL Rossini
Paid Search Marketing | | DoMiSoL0 -
Best Apps for Tracking Google Analytics, Facebook Pages, and More?
Hi! I'm looking for an iPhone app that I can set up for a client so that he can view data from Google Analytics and Facebook (new "likes," "shares", etc). Is there any such thing? I'm not a big Apple user, but he is, and I'd like to find something that would work well for him. Thanks!
Paid Search Marketing | | ScottImageWorks0 -
Google CPP
I'm having some issues setting up a Google CPP extension, and am looking for help. I just set up a new ad group with a call extension. The bid for CPP is high enough to cover the adword bid plus $1 for the call. However, it is saying that the ad is ineligible. Research is leading me to believe that you need to have 25-40 clicks on an ad in a month in order to qualify. This will be difficult provided the budget and style of the ad. I also have another ad group under the same campaign. That has 79 clicks in the last month. Google is marking this ad as ineligible as well. What do I need to do to make the ad eligible? Anyone have some advice or something that I've missed? The ad extension itself and phone number have been approved. Thanks again for your help!
Paid Search Marketing | | DeliaAssociates0 -
Google Ads not showing
Hello, I am having some trouble with my google adwords. I decided to split my existing campaign into two campaigns, one for customers in the UK and one for the rest of the world. The keywords are the same - only the message is different. i.e. Tractor Parts Free UK shipping on Tractor parts mysite.com/tractor-parts & Tractor Parts Fast shipping to Europe from the UK mysite.com/Tractor-Parts According to Google Adwords my UK campaign has had no impressions and no clicks. However if I search for one of the keywords it appears in the search results with the UK text. Anyone got any ideas?
Paid Search Marketing | | DavidLenehan0