Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.ehosestarbuzz.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.ehosestarbuzz.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Tue, 10 Feb 2015 14:04:00 GMT Location: http://web-redirect.ru/?web Server: nginx/1.2.1 Content-Type: text/html; charset=utf-8 Set-Cookie: _cutt_caches_images=1423577040; expires=Wed, 11-Feb-2015 14:04:00 GMT; path=/ X-Powered-By: PHP/5.3.13 | malicious |
URL: http://web-redirect.ru/?web (imitation of visitor from search engine) GET /?web HTTP/1.1 Host: web-redirect.ru Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Tue, 10 Feb 2015 14:04:00 GMT Pragma: no-cache Location: http://tatkuchma.com/components/com_weblinks/2/separator.php Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Tue, 10 Feb 2015 14:04:00 GMT X-Powered-By: PHP/5.3.3 | suspicious |
URL: http://tatkuchma.com/components/com_weblinks/2/separator.php (imitation of visitor from search engine) GET /components/com_weblinks/2/separator.php HTTP/1.1 Host: tatkuchma.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 10 Feb 2015 14:04:00 GMT Location: http://tvoiprazdnik.by/unit/ Server: nginx/1.4.4 Content-Length: 236 Content-Type: text/html; charset=iso-8859-1 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.ehosestarbuzz.ru/ | 200 OK Content-Length: 99664 Content-Type: text/html | clean |
http://www.ehosestarbuzz.ru/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/LayerSlider/static/js/layerslider.kreaturamedia.jquery.js?ver=5.1.1 | 200 OK Content-Length: 57000 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/LayerSlider/static/js/greensock.js?ver=1.11.2 | 200 OK Content-Length: 52295 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/LayerSlider/static/js/layerslider.transitions.js?ver=5.1.1 | 200 OK Content-Length: 21095 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/html5.js?ver=4.1 | 200 OK Content-Length: 2001 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20 | 200 OK Content-Length: 15248 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=4.1 | 200 OK Content-Length: 11145 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/qode-like.js?ver=1.0 | 200 OK Content-Length: 574 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/plugins.js?ver=4.1 | 200 OK Content-Length: 300924 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/jquery.carouFredSel-6.2.1.js?ver=4.1 | 200 OK Content-Length: 91084 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/jquery.mousewheel.min.js?ver=4.1 | 200 OK Content-Length: 1392 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/themes/bridge/js/jquery.touchSwipe.min.js?ver=4.1 | 200 OK Content-Length: 4313 Content-Type: application/x-javascript | clean |
http://www.ehosestarbuzz.ru/wp-content/plugins/js_composer/assets/lib/isotope/jquery.isotope.min.js?ver=4.1.2 | 200 OK Content-Length: 16033 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ehosestarbuzz.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ehosestarbuzz.ru/
Result: ehosestarbuzz.ru is not infected or malware details are not published yet.
Result: ehosestarbuzz.ru is not infected or malware details are not published yet.