Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=forum.balitour.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: forum.balitour.net
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 06 Jan 2015 10:03:44 GMT
Location: http://balitour.net
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.4.35-0+deb7u2
...0 bytes of data.
GET / HTTP/1.1
Host: forum.balitour.net
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 06 Jan 2015 10:03:44 GMT
Location: http://balitour.net
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.4.35-0+deb7u2
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: forum.balitour.net
Referer: http://www.google.com/search?q=forum.balitour.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: forum.balitour.net
Referer: http://www.google.com/search?q=forum.balitour.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://forum.balitour.net/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 06 Jan 2015 10:03:44 GMT Location: http://balitour.net Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.35-0+deb7u2 | clean |
http://balitour.net/ | 200 OK Content-Length: 46136 Content-Type: text/html | clean |
http://www.google.com/jsapi | 200 OK Content-Length: 24552 Content-Type: text/javascript | clean |
http://balitour.net/wp-content/cache/minify/000000/PctbCoAgEEDRDfnotZC2YDCmkc40ToW7TyL6uxy4nV3cHiVAArsVux0ncDXEIFLngIJq_PAPneLKTsCkmNXULszD2729SXt3IUcBTVikNPH0AA.js | 200 OK Content-Length: 134870 Content-Type: application/javascript | clean |
http://balitour.net/wp-content/cache/minify/000000/FcpRDoAgCADQC4XMr87DlBpOsUTavH3z-72ITLbA5FbwB4shm8NHVTJNPiKmrpPShKuPBieKpuqZbc_yOo8VtoQm-gM.js | 200 OK Content-Length: 18756 Content-Type: application/javascript | clean |
http://balitour.net/wp-content/cache/minify/000000/M9RPzs8rSUwu0U3LL8rVNdfPzEvOKU1JLdbPKtYvTi7KLCgpBgA.js | 200 OK Content-Length: 8155 Content-Type: application/javascript | clean |
http://forum.balitour.net/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=31536000 Connection: close Date: Tue, 06 Jan 2015 10:03:45 GMT Location: http://forum.balitour.net/ Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 06 Jan 2016 10:03:45 GMT | clean |