Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: corizza.com.ua
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 18 Sep 2014 06:31:24 GMT
Location: http://www.corizza.com.ua/
Server: nginx/1.0.15
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.corizza.com.ua/xmlrpc.php
X-Powered-By: PHP/5.2.17
...0 bytes of data.
GET / HTTP/1.1
Host: corizza.com.ua
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 18 Sep 2014 06:31:24 GMT
Location: http://www.corizza.com.ua/
Server: nginx/1.0.15
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.corizza.com.ua/xmlrpc.php
X-Powered-By: PHP/5.2.17
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: corizza.com.ua
Referer: http://www.google.com/search?q=corizza.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: corizza.com.ua
Referer: http://www.google.com/search?q=corizza.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://corizza.com.ua/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 18 Sep 2014 06:31:24 GMT Location: http://www.corizza.com.ua/ Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.corizza.com.ua/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://www.corizza.com.ua/ | 200 OK Content-Length: 99734 Content-Type: text/html | clean |
http://www.corizza.com.ua/wp-includes/js/prototype.js?ver=1.6.1 | 200 OK Content-Length: 139854 Content-Type: application/x-javascript | clean |
http://www.corizza.com.ua/wp-includes/js/scriptaculous/wp-scriptaculous.js?ver=1.8.3 | 200 OK Content-Length: 2944 Content-Type: application/x-javascript | clean |
http://www.corizza.com.ua/wp-includes/js/scriptaculous/effects.js?ver=1.8.3 | 200 OK Content-Length: 38471 Content-Type: application/x-javascript | clean |
http://www.corizza.com.ua/wp-content/plugins/lightbox-2/lightbox.js?ver=1.8 | 200 OK Content-Length: 21338 Content-Type: application/x-javascript | clean |
http://informer.gismeteo.ru/flash/fcode.js | 200 OK Content-Length: 637 Content-Type: application/x-javascript | clean |
http://corizza.com.ua/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 18 Sep 2014 06:31:29 GMT Location: http://www.corizza.com.ua/ Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.corizza.com.ua/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://www.corizza.com.ua/test404page.js | 404 Not Found Content-Length: 81188 Content-Type: text/html | clean |
http://www.corizza.com.ua/ | 200 OK Content-Length: 99734 Content-Type: text/html | clean |
http://www.corizza.com.ua/feed/ | 200 OK Content-Length: 38401 Content-Type: text/xml | clean |
http://www.corizza.com.ua/strany/amerika-i-karibskijj-bassejjn/dominikana-dominikanskaya-respublika/dominikana-ceny/ | 200 OK Content-Length: 82996 Content-Type: text/html | clean |
http://www.corizza.com.ua/strany/amerika-i-karibskijj-bassejjn/dominikana-dominikanskaya-respublika/dominikana-ceny/ | 200 OK Content-Length: 82996 Content-Type: text/html | clean |
http://www.corizza.com.ua/strany/ | 200 OK Content-Length: 83379 Content-Type: text/html | clean |
http://www.corizza.com.ua/strany/ | 200 OK Content-Length: 83379 Content-Type: text/html | clean |
http://www.corizza.com.ua/strany/afrika/ | 200 OK Content-Length: 82187 Content-Type: text/html | clean |
http://www.corizza.com.ua/strany/afrika/ | 200 OK Content-Length: 82187 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=corizza.com.ua
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://corizza.com.ua/
Result: corizza.com.ua is not infected or malware details are not published yet.
Result: corizza.com.ua is not infected or malware details are not published yet.