Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=corridosmexicanos.com.mx
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://corridosmexicanos.com.mx/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 22 Dec 2014 12:28:44 GMT Location: http://www.corridosmexicanos.com.mx/ Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: wfvt_66772807=54980e7c7a59f; expires=Mon, 22-Dec-2014 12:58:44 GMT; path=/; httponly X-Pingback: http://www.corridosmexicanos.com.mx/xmlrpc.php | clean |
http://www.corridosmexicanos.com.mx/ | 200 OK Content-Length: 56671 Content-Type: text/html | clean |
http://www.corridosmexicanos.com.mx/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ajax.js?ver=3.9.3 | 200 OK Content-Length: 33 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/persist.js?ver=3.9.3 | 200 OK Content-Length: 24995 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/store.js?ver=3.9.3 | 200 OK Content-Length: 5337 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ngg_store.js?ver=3.9.3 | 200 OK Content-Length: 891 Content-Type: application/javascript | clean |
http://www.corridosmexicanos.com.mx/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/lightbox/static/lightbox_context.js?ver=3.9.3 | 200 OK Content-Length: 890 Content-Type: application/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19470 Content-Type: text/javascript | clean |
http://platform.twitter.com/widgets.js | 200 OK Content-Length: 110239 Content-Type: application/javascript | clean |
http://corridosmexicanos.com.mx/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 22 Dec 2014 12:28:55 GMT Location: http://www.corridosmexicanos.com.mx/ Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: wfvt_66772807=54980e879b74c; expires=Mon, 22-Dec-2014 12:58:55 GMT; path=/; httponly X-Pingback: http://www.corridosmexicanos.com.mx/xmlrpc.php | clean |
http://www.corridosmexicanos.com.mx/test404page.js | 404 Not Found Content-Length: 11140 Content-Type: text/html | clean |
http://www.corridosmexicanos.com.mx/category/corridos-2012/ | 200 OK Content-Length: 48059 Content-Type: text/html | clean |
http://www.corridosmexicanos.com.mx/category/el-komander/ | 200 OK Content-Length: 47030 Content-Type: text/html | clean |
http://www.corridosmexicanos.com.mx/category/gerardo-ortiz/ | 200 OK Content-Length: 47767 Content-Type: text/html | clean |
http://www.corridosmexicanos.com.mx/2012/03/gerardo-ortiz-soy-don-chalo/ | 200 OK Content-Length: 47581 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._zem_rp_blog_id = '7072946'; window._zem_rp_post_id = '499'; window._zem_rp_thumbnails = true; window._zem_rp_post_title = 'Gerardo+Ortiz+%E2%80%93+Soy+Don+Chalo'; window._zem_rp_post_tags = ['narco+corridos', 'gerardo+ortiz', 'soi', 'ortiz', 'don']; window._zem_rp_static_base_url = 'http://content.zemanta.com/static/'; window._zem_rp_wp_ajax_url = 'http://www.corridosmexicanos.com.mx/wp-admin/admin-ajax.php'; window._zem_rp_plugin_version = '1.8.1'; window._zem_rp_num_rel_posts = '4'; window._zem_rp_remote_recommendations = false; Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: corridosmexicanos.com.mx
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 22 Dec 2014 12:28:44 GMT
Location: http://www.corridosmexicanos.com.mx/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_66772807=54980e7c7a59f; expires=Mon, 22-Dec-2014 12:58:44 GMT; path=/; httponly
X-Pingback: http://www.corridosmexicanos.com.mx/xmlrpc.php
...0 bytes of data.
GET / HTTP/1.1
Host: corridosmexicanos.com.mx
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 22 Dec 2014 12:28:44 GMT
Location: http://www.corridosmexicanos.com.mx/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_66772807=54980e7c7a59f; expires=Mon, 22-Dec-2014 12:58:44 GMT; path=/; httponly
X-Pingback: http://www.corridosmexicanos.com.mx/xmlrpc.php
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: corridosmexicanos.com.mx
Referer: http://www.google.com/search?q=corridosmexicanos.com.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: corridosmexicanos.com.mx
Referer: http://www.google.com/search?q=corridosmexicanos.com.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.