Website is flagged as Compromised Site by Google
-
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]netWe have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.
-
@Alex-Montarev We actually have a Drupal site and we're having the same issue...
-
Hello
Thanks for the heads-up. We'll look into it immediately and take the necessary steps to resolve the issue.
-
Update: I have also raised this on Google community: https://support.google.com/google-ads/thread/280600750?hl=vi&sjid=17667827560611966802-AP
and one of the member, who claims to be an IT engineer and security researcher, replied that the issue is caused by the library polyfill. The person said that a popular library got compromised and resulted in many site affected by this attack.
We are checking on this and if it is possible, you all can also take a look at this on your sides as well.
Hope this helps.
-
@Pedropeit thank you for the information and the offer to help. I really appreciate it!
Our website provider have tried to scan our website using these tools: Sucuri SiteCheck, VirusTotal, Quttera but we haven't found any unsual things.
We are trying to do a deeper scan at the moment but we are leaning on the possibility that this is a false alarm from Google. If so, do you know how we can reach out to more relevant personnel from Google to ask about this issue other than the general support team?
Thank you!
-
@Alex-Montarev we do not use Shopify, unfortunately. We are still in process of solving this.
We reached out to Google Ads support but only get some generic answers. Have you able to solve it already?
-
Hello there.
I see that in your website, you are using https://polyfill.io/v3/polyfill.min.js?features=IntersectionObserver%2CIntersectionObserverEntry . You will need to remove it as it is a compromised CDN, and it can make your website run arbitrary code. -
@ManpowerVietnam said in Website is flagged as Compromised Site by Google:
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]net
We have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.I understand the frustration you're experiencing with the Google Ads suspension due to a "Compromised Site" issue. Here are some steps and tools you can use to deeply scan your website and address this problem:
Manual Inspection:
Check Source Code: Manually inspect the source code of the affected page for any references to the malicious links (googie-anaiytics[.]com, vty68[.]net). These might be hidden in scripts or embedded in iframes.
Browser Developer Tools: Use browser developer tools (F12) to inspect the network activity on the affected page. Look for any unexpected network requests to the malicious domains.
Online Security Scanners:Sucuri SiteCheck: This free tool scans your website for malware, blacklisting status, injected spam, and defacements. You can access it here.
VirusTotal: Submit the URL of the affected page to VirusTotal to get a report from multiple antivirus engines. You can use it here.
Quttera: This tool provides a detailed report on any suspicious content or malware on your website. Try it here.
Web Security Plugins:Wordfence (for WordPress): If your website is running on WordPress, install Wordfence Security. It provides comprehensive scanning and firewall protection.
MalCare (for WordPress): Another WordPress security plugin that offers malware scanning and removal.
Server-Side Scanning:ClamAV: If you have access to your server, you can run ClamAV, an open-source antivirus engine, to scan your web directories for malware.
Maldet (Linux Malware Detect): This tool can be used on Linux servers to find and quarantine malware.
Professional Help:If the issue persists, consider hiring a professional web security service or a cybersecurity expert to perform an in-depth analysis and cleanup.
Once you've performed a thorough scan and cleanup, you should:Submit a Review Request: Inform Google Ads support that you've taken steps to clean your site and request a review.
Monitor Regularly: Set up regular scans and monitoring to prevent future compromises.
If anyone in the community has faced a similar issue or has additional tools and tips to share, your input would be greatly appreciated.Please let me know if you need any further assistance or specific information. I'm here to help.
Best regards,
-
We're having the same issue with our Shopify store, starting a few days ago. Google says the same thing, this "googie anaiytics" link that does not exist on our site.
Are you using Shopify? I'm wondering if it's a common Shopify app that's hacked or something that's causing this issue.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Keyword & negative keyword overlap
So I just read your blog on quality score and after reading the negative keyword section I'm a little confused and I need clarification. In that paragraph you mentioned about not overlapping your negative keywords with your active keywords and you used an example of dog food and dog bed. So my question is, if you put the word dog bed into the negative keyword list isn't the word dog the over lap word? Would you ad not show because the word dog is in the active keyword list?
Paid Search Marketing | | Vallerinspects0 -
Unsolved Google Ads Not Getting Clicks or Impressions
I have been running some google ads - in the past 7 days I've had no clicks or impressions is this common? #ads
Paid Search Marketing | | PermaTherm0 -
What are the best advertising platforms for B2C?
Recently, Google ads stop being as effective. Same ads, cost, and web pages, but not getting the same results. Our budget is $4500/mo and need to get at least $25,000 in sales before increasing the budget. What ad platforms have you had success with?
Paid Search Marketing | | seotools4me0 -
Google Merchant Center product reviews
My googlefu is not good enough to put the words together to find an answer for this, but I am sure there is one out there. I am making a review feed for a client's site to submit their product reviews to google merchant center. But one problem we are having is that the reviews are generalized, like how amazon does it. A sample product would be Whey Protein, this product is available in 4 different sizes and has 4 different GTIN's (one for each size). But the reviews we collect are just for the base product of Whey Protein. What I am trying to figure out, is if I can assign a parent GTIN, then correlate the reviews to that GTIN and then let them populate for the child GTIN's some how.
Paid Search Marketing | | LesleyPaone0 -
A Call From Google (Not a Question but the Moderators said to Put this Here)
This is not going to be a long post but I wanted to get something out there that a lot of other business owners might not understand. I have several different PPC campaigns that my business partner and I personally run. The campaigns are all doing quite well with a high rate of return. Never has Google contacted me (other than for surveys, which I did wind up receiving 5 blue gym bags with the Google insignia on them) and never did I think they would. The campaign they called me on wasn’t a particularly large campaign. Right now the PPC spend is around 3000/month. I understand this isn’t a little bit of money, but at the same time it’s not in the millions like most of Google’s top sites. The thing that concerned me most was the reason for their call. A nice woman introduced herself and said that the campaigns were nicely run except for a few changes. She went on to tell me of a couple of updates in the PPC realm (this happened to me yesterday – Feb 28). She said within the past few months they were rolling out a new way to target their content network and for most people they were able to save 35% (that was a number she mentioned) with the tactics she was going to suggest. My background lies in mathematics and finance (somewhat related) and I tend to know when I am either being sold or being tricked into being sold. Through the whole list of things she mentioned that would help as she was walking me through she mentioned that it was a good idea to up the bid on the content network. That way we would have more chances of being seen and it would help with out conversions. This by itself seems like decent advice, but our bid for the content network is not cheap. If they are calling every small – medium business and telling them to up their bids, we are going to have a dilemma on our hands. The dilemma being that the AdWords placement is going to cost a heck of a lot more. She said that even if we up our bid, we are not likely to pay the full amount. She wants us to have a repeat conversation on Monday. One side of me was a little upset after the conversation but all they are doing is simply up-selling. They are raising the rates through what I guess are fair business practices. A lot of business owners might just take the advice of a Google representative and not think twice about it. This means we have thousands to hundreds of thousands of people at this very moment upping the bid on their content network. If they can even get a small proportion of people to increase their bids - let's say 10% - the other 90% will start getting less shows and eventually increase their bids. Also, the people that have higher bid amounts in but aren't paying the full amount will start getting closer and closer to the amount they put in as their maximum bid. This wouldn’t be alarming to me but this is the first and only time I have ever heard from a Google representative. I can’t say I didn’t see this coming but at the same time I was definitely taken aback. I am curious to know what the MOZ community has to say.
Paid Search Marketing | | JacobEdward0 -
Noob Question on franchise sites
What is the best way to approach these franchise sites that have tons of location pages with 95% same content on every page? Each location has its own unique url that just redirects to the main franchise location page, but with no uniqueness or independent blog is it even possible to get a page like this ranked locally or is the best route PPC?
Paid Search Marketing | | satoridesign0 -
Why doesn't exact match appear to be working for me in Google AdWords tool?
Hi guys, I recently read Rand's article here and tried out the exact match symbols on my keywords. However, these don't appear to be working for me as the results aren't showing up as they do in the above SEOmoz article (attached screenshot). What am I doing wrong? Google_AdWords__Keyword_Tool-20130511-115528.jpg.jpg?resizeSmall&width=832
Paid Search Marketing | | featherseo0 -
targeting different keywords for site
A site i am working on seakayakingdevon.co.uk, currently optimising for sea kayaking wishes to target alternative keywords such as - canoeing, canoe trips etc. more importantly rank higher than a dedicated local canoeing center site. The issue is he provides kayaking trips and courses and not canoeing but believes a a large percent of his targeted market actual mistakenly searches for canoeing when they actually mean kayaking or simply have no preference - i.e kayaks are often confused with canoes especially with people who have no preference but are more inclined to search using terms related to canoeing, canoe day trip etc. As his site is geared to what he actually provides, I have advised that he would struggle to target such terms as he has no content relating to canoeing and risks the overall ranking positions and SEO efforts for sea kayaking terms.( As these would have to be diluted and would no longer relate to the actual page content.) What method could he deploy without sacrificing the sea kayaking optimisation? I realise he could optimise the site and content for both but question just how successful this would be when compared with the loss of dedicated sea kayaking audience. Is it really worth targeting keywords for service he doesn't provide? On a separate note the site is doing reasonably well since optmisation for localised serch terms but would like to target a wider UK audience as well i.e. tourism to the area. thanks
Paid Search Marketing | | Bristolweb0