Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=annuity-lead.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://annuity-lead.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: annuity-lead.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=2678400
Connection: close
Date: Mon, 15 Sep 2014 11:30:26 GMT
Location: http://www.annuity-lead.com/
Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Vary: Cookie,Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 16 Oct 2014 11:30:26 GMT
X-Pingback: http://www.annuity-lead.com/xmlrpc.php
X-Powered-By: PHP/5.3.21
...0 bytes of data.
GET / HTTP/1.1
Host: annuity-lead.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=2678400
Connection: close
Date: Mon, 15 Sep 2014 11:30:26 GMT
Location: http://www.annuity-lead.com/
Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Vary: Cookie,Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 16 Oct 2014 11:30:26 GMT
X-Pingback: http://www.annuity-lead.com/xmlrpc.php
X-Powered-By: PHP/5.3.21
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: annuity-lead.com
Referer: http://www.google.com/search?q=annuity-lead.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: annuity-lead.com
Referer: http://www.google.com/search?q=annuity-lead.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://annuity-lead.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=2678400 Connection: close Date: Mon, 15 Sep 2014 11:30:26 GMT Location: http://www.annuity-lead.com/ Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Vary: Cookie,Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 16 Oct 2014 11:30:26 GMT X-Pingback: http://www.annuity-lead.com/xmlrpc.php X-Powered-By: PHP/5.3.21 | clean |
http://www.annuity-lead.com/ | 200 OK Content-Length: 24359 Content-Type: text/html | clean |
http://www.annuity-lead.com/wp-includes/js/jquery/jquery.js,qver=1.11.0.pagespeed.jm.w1TUh-8_Wh.js | 200 OK Content-Length: 97150 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-includes,_js,_jquery,_jquery-migrate.min.js,qver==1.2.1+wp-content,_plugins,_magic-action-box-pro,_assets,_js,_actionbox-helper.js,qver==3.9.1.pagespeed.jc.lCxwAWvpyL.js | 200 OK Content-Length: 8605 Content-Type: application/javascript | clean |
https://apis.google.com/js/platform.js | 200 OK Content-Length: 36362 Content-Type: application/javascript | clean |
http://www.annuity-lead.com/wp-content/themes,_the-box,_js,_small-menu.js,qver==20120206+plugins,_magic-action-box-pro,_assets,_js,_responsive-videos.js,qver==2.14.1+plugins,_wysija-newsletters,_js,_validate,_languages,_jquery.validationEngine-en.js,qver==2.6.8.pagespeed.jc.laqLJUcGie.js | 200 OK Content-Length: 8439 Content-Type: application/javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/wysija-newsletters/js/validate/jquery.validationEngine.js,qver=2.6.8.pagespeed.jm.abo7JFW2V0.js | 200 OK Content-Length: 39266 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/wysija-newsletters/js/front-subscribers.js?ver=2.6.8 | 200 OK Content-Length: 4152 Content-Type: application/x-javascript | clean |
http://annuity-lead.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 15 Sep 2014 11:30:34 GMT Pragma: no-cache Location: http://www.annuity-lead.com/test404page.js Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Vary: Cookie,Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.annuity-lead.com/xmlrpc.php X-Powered-By: PHP/5.3.21 | clean |
http://www.annuity-lead.com/test404page.js | 404 Not Found Content-Length: 13350 Content-Type: text/html | clean |
http://www.annuity-lead.com/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 97383 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 8181 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/magic-action-box-pro/assets/js/actionbox-helper.js?ver=3.9.1 | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/themes/the-box/js/small-menu.js?ver=20120206 | 200 OK Content-Length: 2235 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/magic-action-box-pro/assets/js/responsive-videos.js?ver=2.14.1 | 200 OK Content-Length: 1823 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery.validationEngine-en.js?ver=2.6.8 | 200 OK Content-Length: 11225 Content-Type: application/x-javascript | clean |
http://www.annuity-lead.com/wp-content/plugins/wysija-newsletters/js/validate/jquery.validationEngine.js?ver=2.6.8 | 200 OK Content-Length: 72726 Content-Type: application/x-javascript | clean |