Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ena1.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 08 Oct 2014 17:04:47 GMT
Server: Apache
Vary: Host,Accept-Encoding,User-Agent
Content-Type: text/html
Last-Modified: Thu, 01 Jan 1970 00:00:00 GMT
X-Powered-By: W3 Total Cache/0.9.4
GET / HTTP/1.1
Host: ena1.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 08 Oct 2014 17:04:47 GMT
Server: Apache
Vary: Host,Accept-Encoding,User-Agent
Content-Type: text/html
Last-Modified: Thu, 01 Jan 1970 00:00:00 GMT
X-Powered-By: W3 Total Cache/0.9.4
Second query (visit from search engine):
GET / HTTP/1.1
Host: ena1.org
Referer: http://www.google.com/search?q=ena1.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ena1.org
Referer: http://www.google.com/search?q=ena1.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.ena1.org/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 08 Oct 2014 17:04:45 GMT Location: http://ena1.org/ Server: Apache Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Set-Cookie: quick_chat_alias=Guest_635; path=/ Set-Cookie: wfvt_262752445=54356eaf1de04; expires=Wed, 08-Oct-2014 17:34:47 GMT; path=/; httponly Set-Cookie: wphcu_seen=1; expires=Thu, 09-Oct-2014 17:04:47 GMT X-Pingback: http://ena1.org/xmlrpc.php X-Powered-By: W3 Total Cache/0.9.4 | clean |
http://ena1.org/ | 200 OK Content-Length: 66671 Content-Type: text/html | clean |
http://ena1.org/wp-content/plugins/mootools-collapsing-archives/js/mootools-1.2.5-core-yc.js?ver=1.2.5 | 200 OK Content-Length: 66798 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/mootools-collapsing-archives/js/mootools-1.2.5.1-more-yc.js?ver=1.2.5 | 200 OK Content-Length: 20386 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/mootools-collapsing-archives/js/collapsFunctions.js?ver=1.2.5 | 200 OK Content-Length: 3609 Content-Type: application/javascript | clean |
http://ena1.org/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://ena1.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/themes/wp_informati5-v1.3/panel/scripts/modernizr-2.6.2.js?ver=4.0 | 200 OK Content-Length: 9288 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/scroll-top-and-bottom/js/script.js?ver=4.0 | 200 OK Content-Length: 540 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/sliding-social-icons/js/site/sc_social_slider.js?ver=1.61 | 200 OK Content-Length: 875 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/slideshow-gallery/js/gallery.js?ver=1.0 | 200 OK Content-Length: 6804 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/slideshow-gallery/js/colorbox.js?ver=1.3.19 | 200 OK Content-Length: 28444 Content-Type: application/javascript | clean |
http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js | 200 OK Content-Length: 9759 Content-Type: text/javascript | clean |
http://ena1.org/wp-content/themes/wp_informati5-v1.3/panel/scripts/fancybox-2.1.5/jquery.fancybox.pack.js?ver=2.1.5 | 200 OK Content-Length: 23135 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20 | 200 OK Content-Length: 15248 Content-Type: application/javascript | clean |
http://ena1.org/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.9.3 | 200 OK Content-Length: 9658 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ena1.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ena1.org/
Result: ena1.org is not infected or malware details are not published yet.
Result: ena1.org is not infected or malware details are not published yet.