Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: femenino.info
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=3600
Connection: close
Date: Fri, 16 Jan 2015 23:55:12 GMT
Location: http://www.ocio.net/categoria/mujer/
Server: Apache/2.2.15 (CentOS)
Content-Length: 244
Content-Type: text/html; charset=iso-8859-1
Expires: Sat, 17 Jan 2015 00:55:12 GMT
...244 bytes of data.
GET / HTTP/1.1
Host: femenino.info
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=3600
Connection: close
Date: Fri, 16 Jan 2015 23:55:12 GMT
Location: http://www.ocio.net/categoria/mujer/
Server: Apache/2.2.15 (CentOS)
Content-Length: 244
Content-Type: text/html; charset=iso-8859-1
Expires: Sat, 17 Jan 2015 00:55:12 GMT
...244 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: femenino.info
Referer: http://www.google.com/search?q=femenino.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: femenino.info
Referer: http://www.google.com/search?q=femenino.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://femenino.info/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=3600 Connection: close Date: Fri, 16 Jan 2015 23:55:12 GMT Location: http://www.ocio.net/categoria/mujer/ Server: Apache/2.2.15 (CentOS) Content-Length: 244 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 17 Jan 2015 00:55:12 GMT | clean |
http://www.ocio.net/categoria/mujer/ | 200 OK Content-Length: 77793 Content-Type: text/html | clean |
http://www.ocio.net/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20 | 200 OK Content-Length: 15248 Content-Type: application/x-javascript | clean |
http://www.ocio.net/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=4.0.3 | 200 OK Content-Length: 9658 Content-Type: application/x-javascript | clean |
http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201503 | 200 OK Content-Length: 9301 Content-Type: application/x-javascript | clean |
http://s.gravatar.com/js/gprofiles.js?ver=2015Janaa | 200 OK Content-Length: 21442 Content-Type: application/x-javascript | clean |
http://www.ocio.net/wp-content/plugins/jetpack/modules/wpgroho.js?ver=4.1 | 200 OK Content-Length: 959 Content-Type: application/x-javascript | clean |
http://www.ocio.net/wp-content/themes/multinews/js/plugins.min.js?ver=1.0 | 200 OK Content-Length: 133670 Content-Type: application/x-javascript | clean |
http://www.ocio.net/wp-content/themes/multinews/js/main.js?ver=1.0 | 200 OK Content-Length: 46059 Content-Type: application/x-javascript | clean |
http://www.ocio.net/wp-content/plugins/js_composer/assets/lib/prettyphoto/js/jquery.prettyPhoto.js?ver=4.3.4 | 200 OK Content-Length: 22060 Content-Type: application/x-javascript | clean |
http://stats.wp.com/e-201503.js | 200 OK Content-Length: 2332 Content-Type: application/x-javascript | clean |
http://femenino.info/contactar/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=3600 Connection: close Date: Fri, 16 Jan 2015 23:55:48 GMT Location: http://www.ocio.net/contactar/ Server: Apache/2.2.15 (CentOS) Content-Length: 238 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 17 Jan 2015 00:55:48 GMT | clean |
http://www.ocio.net/contactar/ | 200 OK Content-Length: 42978 Content-Type: text/html | clean |
http://www.ocio.net/wp-includes/js/comment-reply.min.js?ver=4.1 | 200 OK Content-Length: 757 Content-Type: application/x-javascript | clean |
http://femenino.info/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=3600 Connection: close Date: Fri, 16 Jan 2015 23:55:48 GMT Location: http://www.ocio.net/categoria/mujer/test404page.js Server: Apache/2.2.15 (CentOS) Content-Length: 258 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 17 Jan 2015 00:55:48 GMT | clean |
http://www.ocio.net/categoria/mujer/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 16 Jan 2015 23:52:14 GMT Pragma: no-cache Location: http://www.ocio.net Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT CF-Cache-Status: MISS CF-RAY: 1a9e39b9e14d05db-WAW Set-Cookie: __cfduid=de7548ff2aa7037d76a9c1ba69b771e4e1421452333; expires=Sat, 16-Jan-16 23:52:13 GMT; path=/; domain=.ocio.net; HttpOnly X-Powered-By: PHP/5.4.36 | clean |
http://www.ocio.net/ | 200 OK Content-Length: 111081 Content-Type: text/html | clean |
http://www.ocio.net/wp-content/plugins/js_composer/assets/js/js_composer_front.js?ver=4.3.4 | 200 OK Content-Length: 23901 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=femenino.info
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://femenino.info/
Result: femenino.info is not infected or malware details are not published yet.
Result: femenino.info is not infected or malware details are not published yet.