Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=capitalchange.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: capitalchange.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 25 Dec 2014 10:37:26 GMT
Pragma: no-cache
Server: nginx/1.6.2
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=9e4588afaf3fcc142a6667325886dfea; path=/
Set-Cookie: dgxdonate=9e4588afaf3fcc142a6667325886dfea; expires=Thu, 01-Jan-2015 10:37:25 GMT; path=/; domain=capitalchange.org
X-Pingback: http://capitalchange.org/xmlrpc.php
GET / HTTP/1.1
Host: capitalchange.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 25 Dec 2014 10:37:26 GMT
Pragma: no-cache
Server: nginx/1.6.2
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=9e4588afaf3fcc142a6667325886dfea; path=/
Set-Cookie: dgxdonate=9e4588afaf3fcc142a6667325886dfea; expires=Thu, 01-Jan-2015 10:37:25 GMT; path=/; domain=capitalchange.org
X-Pingback: http://capitalchange.org/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: capitalchange.org
Referer: http://www.google.com/search?q=capitalchange.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: capitalchange.org
Referer: http://www.google.com/search?q=capitalchange.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.capitalchange.org/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 25 Dec 2014 10:37:24 GMT Pragma: no-cache Location: http://capitalchange.org/ Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=6cab07eeaca4bb94e81cd3166eaeabfd; path=/ Set-Cookie: dgxdonate=6cab07eeaca4bb94e81cd3166eaeabfd; expires=Thu, 01-Jan-2015 10:37:23 GMT; path=/; domain=www.capitalchange.org X-Pingback: http://capitalchange.org/xmlrpc.php | clean |
http://capitalchange.org/ | 200 OK Content-Length: 27270 Content-Type: text/html | clean |
http://capitalchange.org/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ajax.js?ver=3.9.3 | 200 OK Content-Length: 33 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.easing.1.3.js?ver=3.9.3 | 200 OK Content-Length: 9827 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.cycle.all.min.js?ver=3.9.3 | 200 OK Content-Length: 50111 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.tools.min.js?ver=3.9.3 | 200 OK Content-Length: 10035 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.prettyPhoto.js?ver=3.9.3 | 200 OK Content-Length: 23508 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/menu_min.js?ver=3.9.3 | 200 OK Content-Length: 1474 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/colortip-1.0-jquery.js?ver=3.9.3 | 200 OK Content-Length: 3362 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.popeye-2.0.4.min.js?ver=3.9.3 | 200 OK Content-Length: 7696 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.validate.js?ver=3.9.3 | 200 OK Content-Length: 35367 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.form.js?ver=3.9.3 | 200 OK Content-Length: 26379 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jquery.tweet.js?ver=3.9.3 | 200 OK Content-Length: 8515 Content-Type: application/javascript | clean |
http://capitalchange.org/wp-content/themes/rttheme-15-premium-wordpress-theme/rttheme15/js/jflickrfeed.min.js?ver=3.9.3 | 200 OK Content-Length: 1731 Content-Type: application/javascript | clean |