Website is flagged as Compromised Site by Google
-
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]netWe have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.
-
Your website is being flagged as compromised, even though multiple scans have shown no issues. You may want to consider using advanced security tools like Sucuri or Wordfence, which offer more thorough scans for hidden malware or vulnerabilities. Also, make sure that all external scripts and plugins are secure and up-to-date. It could be helpful to consult a cybersecurity expert to conduct a comprehensive audit and address any potential security gaps.
-
We would most definitely recommend contacting a freelancer or an SEO agency for help. We say this because if the website has incurred a Google manual action penalty, then this can severely damage your business's organic SEO for a long time unless fixed, Therefore, you need to contact an expert SEO consultant for advice straightaway.
-
@Alex-Montarev We actually have a Drupal site and we're having the same issue...
-
Hello
Thanks for the heads-up. We'll look into it immediately and take the necessary steps to resolve the issue.
-
Update: I have also raised this on Google community: https://support.google.com/google-ads/thread/280600750?hl=vi&sjid=17667827560611966802-AP
and one of the member, who claims to be an IT engineer and security researcher, replied that the issue is caused by the library polyfill. The person said that a popular library got compromised and resulted in many site affected by this attack.
We are checking on this and if it is possible, you all can also take a look at this on your sides as well.
Hope this helps.
-
@Pedropeit thank you for the information and the offer to help. I really appreciate it!
Our website provider have tried to scan our website using these tools: Sucuri SiteCheck, VirusTotal, Quttera but we haven't found any unsual things.
We are trying to do a deeper scan at the moment but we are leaning on the possibility that this is a false alarm from Google. If so, do you know how we can reach out to more relevant personnel from Google to ask about this issue other than the general support team?
Thank you!
-
@Alex-Montarev we do not use Shopify, unfortunately. We are still in process of solving this.
We reached out to Google Ads support but only get some generic answers. Have you able to solve it already?
-
Hello there.
I see that in your website, you are using https://polyfill.io/v3/polyfill.min.js?features=IntersectionObserver%2CIntersectionObserverEntry . You will need to remove it as it is a compromised CDN, and it can make your website run arbitrary code. -
@ManpowerVietnam said in Website is flagged as Compromised Site by Google:
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]net
We have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.I understand the frustration you're experiencing with the Google Ads suspension due to a "Compromised Site" issue. Here are some steps and tools you can use to deeply scan your website and address this problem:
Manual Inspection:
Check Source Code: Manually inspect the source code of the affected page for any references to the malicious links (googie-anaiytics[.]com, vty68[.]net). These might be hidden in scripts or embedded in iframes.
Browser Developer Tools: Use browser developer tools (F12) to inspect the network activity on the affected page. Look for any unexpected network requests to the malicious domains.
Online Security Scanners:Sucuri SiteCheck: This free tool scans your website for malware, blacklisting status, injected spam, and defacements. You can access it here.
VirusTotal: Submit the URL of the affected page to VirusTotal to get a report from multiple antivirus engines. You can use it here.
Quttera: This tool provides a detailed report on any suspicious content or malware on your website. Try it here.
Web Security Plugins:Wordfence (for WordPress): If your website is running on WordPress, install Wordfence Security. It provides comprehensive scanning and firewall protection.
MalCare (for WordPress): Another WordPress security plugin that offers malware scanning and removal.
Server-Side Scanning:ClamAV: If you have access to your server, you can run ClamAV, an open-source antivirus engine, to scan your web directories for malware.
Maldet (Linux Malware Detect): This tool can be used on Linux servers to find and quarantine malware.
Professional Help:If the issue persists, consider hiring a professional web security service or a cybersecurity expert to perform an in-depth analysis and cleanup.
Once you've performed a thorough scan and cleanup, you should:Submit a Review Request: Inform Google Ads support that you've taken steps to clean your site and request a review.
Monitor Regularly: Set up regular scans and monitoring to prevent future compromises.
If anyone in the community has faced a similar issue or has additional tools and tips to share, your input would be greatly appreciated.Please let me know if you need any further assistance or specific information. I'm here to help.
Best regards,
-
We're having the same issue with our Shopify store, starting a few days ago. Google says the same thing, this "googie anaiytics" link that does not exist on our site.
Are you using Shopify? I'm wondering if it's a common Shopify app that's hacked or something that's causing this issue.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
What are the best advertising platforms for B2C?
Recently, Google ads stop being as effective. Same ads, cost, and web pages, but not getting the same results. Our budget is $4500/mo and need to get at least $25,000 in sales before increasing the budget. What ad platforms have you had success with?
Paid Search Marketing | | seotools4me0 -
"Duplicate without user-selected canonical” - impact to Google Ads costs
Hello, we are facing some issues on our project and we would like to get some advice. Scenario
Paid Search Marketing | | Alex_Pisa
We run several websites (www.brandName.com, www.brandName.be, www.brandName.ch, etc..) all in French language . All sites have nearly the same content & structure, only minor text (some headings and phone numbers due to different countries are different). There are many good quality pages, but again they are the same over all domains. Current solution
Currently we don’t use canonicals, instead we use rel="alternate" hreflang="x-default": <link rel="alternate" hreflang="fr-BE" href="https://www.brandName.be/" /> <link rel="alternate" hreflang="fr-CA" href="https://www.brandName.ca/" /> <link rel="alternate" hreflang="fr-CH" href="https://www.brandName.ch/" /> <link rel="alternate" hreflang="fr-FR" href="https://www.brandName.fr/" /> <link rel="alternate" hreflang="fr-LU" href="https://www.brandName.lu/" /> <link rel="alternate" hreflang="x-default" href="https://www.brandName.com/" /> Naturally this si reflected in ""Duplicate without user-selected canonical” . Issue
We create the same ad in Google Ads for 2 domains. So the content is mostly identical, ads are identical, target URLs differ only in domain. Yet Google Ads “Quality score” is different (10/10 vs. 6/10) and “Landing page experience” is very different (Above average vs. Average). Some members of our team think lower “Landing page experience” increases the Google Ads costs, which I personally don't believe, but I want to double check. Question: Can “Duplicate without user-selected canonical” issue decrease the “Landing page experience” rating and as result can it cause higher Google ads costs? Any suggestions/ideas appreciated, thanks. Regards.0 -
Google Account verification requires phone number - too many clients!
Hello, all! I like to create a Google Account for my smaller clients, so that I can associate Analytics, AdWords, GMB, etc. all with the same account. Problem: I've used my phone number too many times, so I can't get the new account verified. I've also used all three of the other phones in our family. 🙂 I tried using the "Burner" iPhone app to create a new number, but apparently the all-knowing Google even has info on phone numbers, as it returned "This phone number cannot be used for verification." I'm sure that there's an obvious solution out there - who among you has found it, and is willing to share?! 🙂
Paid Search Marketing | | measurableROI0 -
Can you market to someone 30 days AFTER they visit your site via PPC?
Hi all, I'm looking to market to visitors 30 days AFTER they have been to a website. Their is a coupon this business wants to run every 30 days to its' repeat customers (and if they purchase again); thus, 30 days more will resume. I'm aware that your remarketing list can capture audiences from 30, 60, and 90 days past. I'm talking about future display ads running 30 days after visitor has cookies enabled. Thanks for your help! Cole
Paid Search Marketing | | ColeLusby0 -
Adding Coremetrics Tags with Google Adwords
Hello, I would like to know if it's possible to add Coremetrics tracking tags in Google Adwords while the auto tagging functionnality is on. The point of doing this is to be able to track in both Analytics systems the performance of the PPC campaigns while still having Adwords to use Google Analytics conversion data. Thanks, Guillaume
Paid Search Marketing | | guiberube0 -
I want to try some Google PPC ads on other sites but don't know what i'm doing.
We have seen a massive drop in traffic this year and i am contemplation using banner ads to try to increase sales and also to help with marketing. the problem is i know nothing about doing this. I have used it in the past but to limited success and i was just stabbing in the dark. I have a few questions. Am i better to target keywords related to the product or to the people who may buy my products? Is it better for direct sales or brand awareness? What kind of ROI can i expect if i get it working well? Is it better to pay for the big keywords or pic all the low hanging fruit? Does it work? Should i employ an expert, are they worth it? Any insights into the world of PPc would be a massive help.
Paid Search Marketing | | mark_baird1 -
Report site for duplicate content
Hi All, I know that when a site is using duplicate content (my content) I can report it to Google and have them removed from the index, contact the hosting provider, etc But I was wondering if there is anything I can do to have Google shutdown their PPC campaign? Thanks!
Paid Search Marketing | | Tug-Agency0 -
Your Google AdWords account has been permanently suspended for repeated violation of AdWords or Landing Page and Site policies in this or a related account.
My client nor I received any warning. We even had a google adwords team optimize the account and my rep does not yet know the reason for the ban. Not sure if its related but their google organic rankings dropped significantly at the same time. https://adwords.google.com/support/aw/bin/answer.py?hl=en&answer=164786 Any advice here? Do these Questions get indexed by google? I will ask my client if I can disclose the domain. Is there any way around a permanent ban? They were spending 50K per month. Is this enough to have any clout?
Paid Search Marketing | | webbroi0