Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: californiahia.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 25 Dec 2014 12:02:23 GMT
ETag: "1419508944"
Server: Apache
Vary: Accept-Encoding
Content-Language: en
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Thu, 25 Dec 2014 12:02:24 GMT
Link: </node/32>; rel="canonical",</node/32>; rel="shortlink"
X-Generator: Drupal 7 (http://drupal.org)
GET / HTTP/1.1
Host: californiahia.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 25 Dec 2014 12:02:23 GMT
ETag: "1419508944"
Server: Apache
Vary: Accept-Encoding
Content-Language: en
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Thu, 25 Dec 2014 12:02:24 GMT
Link: </node/32>; rel="canonical",</node/32>; rel="shortlink"
X-Generator: Drupal 7 (http://drupal.org)
Second query (visit from search engine):
GET / HTTP/1.1
Host: californiahia.org
Referer: http://www.google.com/search?q=californiahia.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: californiahia.org
Referer: http://www.google.com/search?q=californiahia.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://californiahia.org/ | 200 OK Content-Length: 31803 Content-Type: text/html | clean |
http://californiahia.org/misc/jquery.js?v=1.4.4 | 200 OK Content-Length: 78602 Content-Type: text/javascript | clean |
http://californiahia.org/misc/jquery.once.js?v=1.2 | 200 OK Content-Length: 2974 Content-Type: text/javascript | clean |
http://californiahia.org/misc/drupal.js?ngwkio | 200 OK Content-Length: 13852 Content-Type: text/javascript | clean |
http://californiahia.org/sites/all/modules/extlink/extlink.js?ngwkio | 200 OK Content-Length: 5759 Content-Type: text/javascript | clean |
http://californiahia.org/sites/all/modules/google_analytics/googleanalytics.js?ngwkio | 200 OK Content-Length: 3411 Content-Type: text/javascript | clean |
http://californiahia.org/sites/all/themes/bartik_plus/scripts/superfish.js?ngwkio | 200 OK Content-Length: 3714 Content-Type: text/javascript | clean |
http://californiahia.org/sites/all/themes/bartik_plus/scripts/bartik_plus.js?ngwkio | 200 OK Content-Length: 696 Content-Type: text/javascript | clean |
http://californiahia.org/sites/californiahia.org/themes/chia/js/jquery.equalheights.js?ngwkio | 200 OK Content-Length: 1021 Content-Type: text/javascript | clean |
http://californiahia.org/news-alerts/feed | 200 OK Content-Length: 11409 Content-Type: application/rss+xml | clean |
http://californiahia.org/test404page.js | 404 Not Found Content-Length: 15103 Content-Type: text/html | clean |
http://californiahia.org/corporate-partner-directory | 200 OK Content-Length: 44839 Content-Type: text/html | clean |
http://californiahia.org/about-us | 200 OK Content-Length: 24550 Content-Type: text/html | clean |
http://californiahia.org/board-directors | 200 OK Content-Length: 24089 Content-Type: text/html | clean |
http://californiahia.org/contact-us | 200 OK Content-Length: 22897 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=californiahia.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://californiahia.org/
Result: californiahia.org is not infected or malware details are not published yet.
Result: californiahia.org is not infected or malware details are not published yet.