Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.ageroute.sn/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.ageroute.sn Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 11 Aug 2014 09:34:19 GMT Location: http://tdson.com/lisinopril Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PleskLin | malicious |
URL: http://tdson.com/lisinopril/ (imitation of visitor from search engine) GET /lisinopril/ HTTP/1.1 Host: tdson.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Connection: close Date: Mon, 11 Aug 2014 11:27:40 GMT Location: http://online-canadapharmacy.com/cardiovascular-diseases/lisinopril.html Server: Apache/2 Content-Length: 317 Content-Type: text/html; charset=iso-8859-1 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.ageroute.sn/ | 200 OK Content-Length: 46730 Content-Type: text/html | clean |
http://www.ageroute.sn/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://www.ageroute.sn/modules/mod_news_pro_gk1/scripts/engine_standard_compressed.js | 200 OK Content-Length: 2207 Content-Type: application/javascript | clean |
http://www.ageroute.sn/components/com_acymailing/js/acymailing_module.js | 200 OK Content-Length: 4380 Content-Type: application/javascript | clean |
http://www.ageroute.sn/modules/mod_gk_tab/scripts/engine_compress.js | 200 OK Content-Length: 2987 Content-Type: application/javascript | clean |
http://www.ageroute.sn/modules/mod_gk_tab/scripts/importer.php?modid=tabmix1&activator=click&animation=1&animationFun=Fx.Transitions.linear&animationType=1&animationSpeed=200&animationInterval=5000&styleType=0&styleSuffix=style1&fixedHeight=0&fixedHeightValue=200&alwaysHide=0 | 200 OK Content-Length: 351 Content-Type: text/javascript | clean |
http://www.ageroute.sn/modules/mod_gk_news_highlighter/scripts/engine_compress.js | 200 OK Content-Length: 3495 Content-Type: application/javascript | clean |
http://www.ageroute.sn/modules/mod_gk_news_highlighter/scripts/importer.php?module_id=news-highlight-1&animation_type=3&animation_speed=250&animation_interval=5000&animation_fun=Fx.Transitions.linear&mouseover=1 | 200 OK Content-Length: 232 Content-Type: text/javascript | clean |
http://www.ageroute.sn/templates/gk_icki_sports/lib/scripts/gk_image_show.js | 200 OK Content-Length: 6673 Content-Type: application/javascript | clean |
http://www.ageroute.sn/templates/gk_icki_sports/lib/scripts/template_scripts.js | 200 OK Content-Length: 3176 Content-Type: application/javascript | clean |
http://www.ageroute.sn/templates/gk_icki_sports/lib/scripts/menu.php?width=1&height=1&opacity=1&animation=1&speed=180 | 200 OK Content-Length: 3391 Content-Type: text/javascript | clean |
http://www.ageroute.sn/media/system/js/validate.js | 200 OK Content-Length: 4246 Content-Type: application/javascript | clean |
http://www.ageroute.sn/modules/mod_slideshow/scripts/horizontal.js | 200 OK Content-Length: 3998 Content-Type: application/javascript | clean |
http://goo.gl/6Jdld7 | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Mon, 11 Aug 2014 09:33:25 GMT Pragma: no-cache Age: 56 Location: http://dbfilesforuser.ru/ML.php Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Mon, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 80:quic X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://dbfilesforuser.ru/ml.php | 404 Not Found Content-Length: 5651 Content-Type: text/html | clean |
http://dbfilesforuser.ru/test404page.js | 404 Not Found Content-Length: 5651 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ageroute.sn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ageroute.sn/
Result: ageroute.sn is not infected or malware details are not published yet.
Result: ageroute.sn is not infected or malware details are not published yet.