Website is flagged as Compromised Site by Google
-
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]netWe have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.
-
@Alex-Montarev We actually have a Drupal site and we're having the same issue...
-
Hello
Thanks for the heads-up. We'll look into it immediately and take the necessary steps to resolve the issue.
-
Update: I have also raised this on Google community: https://support.google.com/google-ads/thread/280600750?hl=vi&sjid=17667827560611966802-AP
and one of the member, who claims to be an IT engineer and security researcher, replied that the issue is caused by the library polyfill. The person said that a popular library got compromised and resulted in many site affected by this attack.
We are checking on this and if it is possible, you all can also take a look at this on your sides as well.
Hope this helps.
-
@Pedropeit thank you for the information and the offer to help. I really appreciate it!
Our website provider have tried to scan our website using these tools: Sucuri SiteCheck, VirusTotal, Quttera but we haven't found any unsual things.
We are trying to do a deeper scan at the moment but we are leaning on the possibility that this is a false alarm from Google. If so, do you know how we can reach out to more relevant personnel from Google to ask about this issue other than the general support team?
Thank you!
-
@Alex-Montarev we do not use Shopify, unfortunately. We are still in process of solving this.
We reached out to Google Ads support but only get some generic answers. Have you able to solve it already?
-
Hello there.
I see that in your website, you are using https://polyfill.io/v3/polyfill.min.js?features=IntersectionObserver%2CIntersectionObserverEntry . You will need to remove it as it is a compromised CDN, and it can make your website run arbitrary code. -
@ManpowerVietnam said in Website is flagged as Compromised Site by Google:
Hi everyone,
We have been running Google Ads for a while now and last week all of our Google Ads were paused with reason Compromised Site. We reached out to Google and they identify this page as one of the affected page: https://manpower.com.vn/vi/dich-vu-san-dau-nguoi-and-tu-van-nhan-su-cap-cao?
The malicious links they found are:
• googie-anaiytics[.]com
• vty68[.]net
We have asked our Website vendor to scan and they found nothing. We would be greatly appreciated if you could help.
I tried Google Search Console and even the tool Google Safe Browsing that Google itself suggested but both the tools showed that our website does not have any malicious links at all. And yet Google Ads support team keeps telling us our page contains these links.
I am wondering if anyone in the community has experienced this before and how did you address this issue.
Or could you guys please help to share any tools that you know can do a deep scan on this page and if possible our entire website to help us identify where the links are located?
Please let me know if you need any additional information from us and I would be happy to provide it.I understand the frustration you're experiencing with the Google Ads suspension due to a "Compromised Site" issue. Here are some steps and tools you can use to deeply scan your website and address this problem:
Manual Inspection:
Check Source Code: Manually inspect the source code of the affected page for any references to the malicious links (googie-anaiytics[.]com, vty68[.]net). These might be hidden in scripts or embedded in iframes.
Browser Developer Tools: Use browser developer tools (F12) to inspect the network activity on the affected page. Look for any unexpected network requests to the malicious domains.
Online Security Scanners:Sucuri SiteCheck: This free tool scans your website for malware, blacklisting status, injected spam, and defacements. You can access it here.
VirusTotal: Submit the URL of the affected page to VirusTotal to get a report from multiple antivirus engines. You can use it here.
Quttera: This tool provides a detailed report on any suspicious content or malware on your website. Try it here.
Web Security Plugins:Wordfence (for WordPress): If your website is running on WordPress, install Wordfence Security. It provides comprehensive scanning and firewall protection.
MalCare (for WordPress): Another WordPress security plugin that offers malware scanning and removal.
Server-Side Scanning:ClamAV: If you have access to your server, you can run ClamAV, an open-source antivirus engine, to scan your web directories for malware.
Maldet (Linux Malware Detect): This tool can be used on Linux servers to find and quarantine malware.
Professional Help:If the issue persists, consider hiring a professional web security service or a cybersecurity expert to perform an in-depth analysis and cleanup.
Once you've performed a thorough scan and cleanup, you should:Submit a Review Request: Inform Google Ads support that you've taken steps to clean your site and request a review.
Monitor Regularly: Set up regular scans and monitoring to prevent future compromises.
If anyone in the community has faced a similar issue or has additional tools and tips to share, your input would be greatly appreciated.Please let me know if you need any further assistance or specific information. I'm here to help.
Best regards,
-
We're having the same issue with our Shopify store, starting a few days ago. Google says the same thing, this "googie anaiytics" link that does not exist on our site.
Are you using Shopify? I'm wondering if it's a common Shopify app that's hacked or something that's causing this issue.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Unsolved Google Ads Subdomain in sitelinks & Composition Change for Strategy Status
I have a basic query but could not find a definite answer on the internet. I am currently running a campaign for the main website of a big education brand and they also have a secondary learning website on subdomain, and I want to add sitelinks of subdomain to the campaign, but I am not sure whether it is allowed or not. The brand I am running ads for is https://www.rauias.com/ and the secondary website is https://compass.rauias.com/ branded slightly different in a subdomain, so should I add the sitelinks of Compass to the main campaign? Also one more silly question My Max Conversion search campaign gave me this status today. "Learning (composition change): Campaigns have been added to or removed from the bid strategy. Google Ads is now adjusting to optimize bids. 5 days left for learning" What does this mean exactly? And Why does it reenter the learning phase whenever I make a small change?
Paid Search Marketing | | rauoff0 -
Unsolved Google Ads Not Getting Clicks or Impressions
I have been running some google ads - in the past 7 days I've had no clicks or impressions is this common? #ads
Paid Search Marketing | | PermaTherm0 -
"Duplicate without user-selected canonical” - impact to Google Ads costs
Hello, we are facing some issues on our project and we would like to get some advice. Scenario
Paid Search Marketing | | Alex_Pisa
We run several websites (www.brandName.com, www.brandName.be, www.brandName.ch, etc..) all in French language . All sites have nearly the same content & structure, only minor text (some headings and phone numbers due to different countries are different). There are many good quality pages, but again they are the same over all domains. Current solution
Currently we don’t use canonicals, instead we use rel="alternate" hreflang="x-default": <link rel="alternate" hreflang="fr-BE" href="https://www.brandName.be/" /> <link rel="alternate" hreflang="fr-CA" href="https://www.brandName.ca/" /> <link rel="alternate" hreflang="fr-CH" href="https://www.brandName.ch/" /> <link rel="alternate" hreflang="fr-FR" href="https://www.brandName.fr/" /> <link rel="alternate" hreflang="fr-LU" href="https://www.brandName.lu/" /> <link rel="alternate" hreflang="x-default" href="https://www.brandName.com/" /> Naturally this si reflected in ""Duplicate without user-selected canonical” . Issue
We create the same ad in Google Ads for 2 domains. So the content is mostly identical, ads are identical, target URLs differ only in domain. Yet Google Ads “Quality score” is different (10/10 vs. 6/10) and “Landing page experience” is very different (Above average vs. Average). Some members of our team think lower “Landing page experience” increases the Google Ads costs, which I personally don't believe, but I want to double check. Question: Can “Duplicate without user-selected canonical” issue decrease the “Landing page experience” rating and as result can it cause higher Google ads costs? Any suggestions/ideas appreciated, thanks. Regards.0 -
Is it possible to link two sites' Search Console to Adwords?
My company is a healthcare organization that has two brands, one that's our 'system' and is mainly adult health services and the other is pediatric only focused care. Both have separate websites. Our SEM is managed by an outside agency. We're in the process of linking our Google Search Consoles to the Adwords account. Our GSC has both of the sites as separate properties, but the Adwords account has all of the campaigns for both brands under one account. Is it possible to link both of the GSC properties in the Adwords account to be able to get accurate information for the Paid & Organic report in Adwords?
Paid Search Marketing | | Kyleroe950 -
Adwords Ad disapproved - Banned product on Site (glutamine)?
We are starting to get ads disapproved. One yesterday, one today. The reason - banned supplement 'glutamine'. Neither of these ads were for glutamine so I assume it's because l-glutamine is sold on the site. The actual ad for l-glutamine landing on the l-glutamine page has not been disapproved? In 2012 Google informed us the glutamine was no longer on the banned list so I'm not sure what's going on here? Has anyone had a similar experience? Is there a solution apart from removing the product entirely?
Paid Search Marketing | | jbk3650 -
Any data for Google results page click through rates?
Hi. Trying to find data for click through rate for the Google search results page? If I run Adwords, do I want a PLA listing or a text listing? Or do I work on PLA + Organic or Text + Organic? What percentages do each position get approximately? E-commerce website. Technology sector. Any help?
Paid Search Marketing | | YNWA0 -
Google Analytics Matched Search Query Not Working
On Google analytics for our clients when you check the Matched Search Query under Traffic Sources > Overview, it says "There is no data for this view.". I have Google searched it and i am not finding my answer to why this is not displaying my information. On my personal analytics account when i clicked on matched search query it displays exactly what the person searched when it trigered my adwords ad. I have no idea why this account doesn't display the same info when it appears to be setup in the same way. Example: If i am broad match targeting the keyword "outdoor sports", and someone searched "Canadian outdoor sports for kids" It would show exactly what they searched under Matched Search Query. Anyone know how to resolve this issue?
Paid Search Marketing | | VITALBGS0 -
Bought old site. Two weeks later, rankings burnt... could this be why?
Hi all, Just joined SEOmoz. Good to be here. I bought an amateur business directory site (not a web directory, but actual profiles of professionals) started in 2004 with page 1 rankings for the top 2 keywords in a professionals niche. Very stable rankings for years and super clean link profile. However I fear I have killed the asset in a matter of weeks, hopefully it's not terminal... here's what I did: #NOTE: I have reverted all changes 2 days ago, but still going down in the rankings. **A) Added Google Analytics:**I think this is what killed it. Why? I didn't realize the analytics account I used had been previously used for a website that was burnt by the search engines, I believe because of duplicate content (I copied a full glossary from a book, didn't know better at the time).Looking at my AWstats the traffic started going down slightly the same day I put the code. It's gone from 170 to 80 visitors per day in 1 week, steadily going down. I rank page 4 or 8 now for what I was page 1 before :(Could it be Google all of a sudden linked that blacklisted (I suppose) Analytics account with the newly purchased site and decided to doom it as well?How can I redeem it?I have taken out the analytics code snippet and deleted the url from the account.OTHER CHANGES: B) On-site SEO: Added H1 in homepage with main keyword (only had H2s before)- Added H1 in each professional profile page "[Professional type] in [Region]" (only had H2s before)- Changed title "[Professional type] - Region: [Region], Professional [Name]The idea behind the changes was to add H1 which in my understanding is very important and was missing, and to include the location in the title, as many searches are of the type "[Professional] in [region]".I think what could have hurt it is now many pages have the same H1.I have reversed all changes.C) I launched a Google Adwords test campaign.In the campaign, because it was a quick test to see how much traffic I could get from the kws, not an attempt to get new sign ups, I simply copy-pasted a landing page from another site and tweaked the text so it made sense to my audience. I run the test for a day or two.
Paid Search Marketing | | Demosthenes
D) Added Hellobar.There was no correlation in time between adding the hellobar and rankings going down, so I don't think this mattered. I have taken it out too.**THANKS FOR YOUR HELP!**I really want to develop a long term asset I can focus on full-time but I fear I may have stupidly doomed the whole website already.0