Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: caristewart.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 23 Sep 2014 18:31:28 GMT
Server: nginx
Content-Type: text/html; charset=UTF-8
Link: <http://wp.me/fxut>; rel=shortlink
X-Pingback: http://caristewart.com/xmlrpc.php
X-Powered-By: PleskLin
GET / HTTP/1.1
Host: caristewart.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 23 Sep 2014 18:31:28 GMT
Server: nginx
Content-Type: text/html; charset=UTF-8
Link: <http://wp.me/fxut>; rel=shortlink
X-Pingback: http://caristewart.com/xmlrpc.php
X-Powered-By: PleskLin
Second query (visit from search engine):
GET / HTTP/1.1
Host: caristewart.com
Referer: http://www.google.com/search?q=caristewart.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: caristewart.com
Referer: http://www.google.com/search?q=caristewart.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.caristewart.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 23 Sep 2014 18:31:27 GMT Location: http://caristewart.com/ Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://caristewart.com/xmlrpc.php X-Powered-By: PleskLin | clean |
http://caristewart.com/ | 200 OK Content-Length: 110107 Content-Type: text/html | clean |
http://caristewart.com/wp-includes/js/jquery/jquery.js?ver=1.7.1 | 200 OK Content-Length: 93889 Content-Type: text/javascript | clean |
http://caristewart.com/wp-includes/js/swfobject.js?ver=2.2 | 200 OK Content-Length: 10220 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995 | 200 OK Content-Length: 26590 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.05 | 200 OK Content-Length: 1750 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/themes/bueno/includes/js/general.js?ver=3.3.1 | 200 OK Content-Length: 697 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/themes/bueno/includes/js/superfish.js?ver=3.3.1 | 200 OK Content-Length: 3912 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/themes/bueno/includes/js/cufon.js?ver=3.3.1 | 200 OK Content-Length: 18257 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/themes/bueno/includes/js/League_Gothic.font.js?ver=3.3.1 | 200 OK Content-Length: 18654 Content-Type: text/javascript | clean |
http://caristewart.com/wp-content/themes/bueno/includes/js/ChunkFive.font.js?ver=3.3.1 | 200 OK Content-Length: 16635 Content-Type: text/javascript | clean |
http://caristewart.com/wp-includes/js/thickbox/thickbox.js?ver=3.1-20111117 | 200 OK Content-Length: 12501 Content-Type: text/javascript | clean |
http://stats.wordpress.com/e-201439.js | 200 OK Content-Length: 824 Content-Type: application/x-javascript | clean |
http://www.caristewart.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Tue, 23 Sep 2014 18:31:35 GMT Pragma: no-cache Location: http://caristewart.com/test404page.js Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Tue, 23 Sep 2014 18:31:35 GMT X-Pingback: http://caristewart.com/xmlrpc.php X-Powered-By: PleskLin | clean |
http://caristewart.com/test404page.js | 404 Not Found Content-Length: 18380 Content-Type: text/html | clean |
http://caristewart.com/category/band/ | 200 OK Content-Length: 27670 Content-Type: text/html | clean |
http://caristewart.com/category/boston/ | 200 OK Content-Length: 45997 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=caristewart.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://caristewart.com/
Result: caristewart.com is not infected or malware details are not published yet.
Result: caristewart.com is not infected or malware details are not published yet.