Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=head2heart.us
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://head2heart.us/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: head2heart.us
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 21 Apr 2014 18:52:11 GMT
Accept-Ranges: bytes
Server: Apache/2.2
Content-Length: 121253
Content-Type: text/html; charset=UTF-8
Last-Modified: Wed, 16 Apr 2014 16:11:31 GMT
Set-Cookie: X-Mapping-jebomepa=AAC9A6D12D64F8CCD3759A92A8BCC6DC; path=/
...121253 bytes of data.
GET / HTTP/1.1
Host: head2heart.us
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 21 Apr 2014 18:52:11 GMT
Accept-Ranges: bytes
Server: Apache/2.2
Content-Length: 121253
Content-Type: text/html; charset=UTF-8
Last-Modified: Wed, 16 Apr 2014 16:11:31 GMT
Set-Cookie: X-Mapping-jebomepa=AAC9A6D12D64F8CCD3759A92A8BCC6DC; path=/
...121253 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: head2heart.us
Referer: http://www.google.com/search?q=head2heart.us
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: head2heart.us
Referer: http://www.google.com/search?q=head2heart.us
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://head2heart.us/ | 200 OK Content-Length: 121253 Content-Type: text/html | clean |
http://head2heart.us//ajax.cloudflare.com/cdn-cgi/nexp/v=3037830340/cloudflare.min.js/ | HTTP/1.1 302 Found Connection: close Date: Mon, 21 Apr 2014 18:52:13 GMT Location: http://goo.gl/1SLEHX Server: Apache/2.2 Content-Length: 271 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-jebomepa=2515B2282E082AA9AFB2EDE18CB5778A; path=/ | clean |
http://goo.gl/1slehx | 404 Not Found Content-Length: 4468 Content-Type: text/html | clean |
http://goo.gl/static/0043.urlshortener.js | 200 OK Content-Length: 64021 Content-Type: text/javascript | clean |
http://head2heart.us/test404page.js | HTTP/1.1 302 Found Connection: close Date: Mon, 21 Apr 2014 18:52:14 GMT Location: http://goo.gl/1SLEHX Server: Apache/2.2 Content-Length: 271 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-jebomepa=BFF377868A75E36C6790607CF072A202; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://goo.gl/test404page.js | 404 Not Found Content-Length: 4476 Content-Type: text/html | clean |
http://goo.gl/ | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Mon, 21 Apr 2014 18:52:14 GMT Location: https://www.google.com/accounts/ServiceLogin?service=urlshortener&continue=http://goo.gl/?authed%3D1&followup=http://goo.gl/?authed%3D1&passive=true&go=true Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Mon, 21 Apr 2014 18:52:14 GMT Alternate-Protocol: 80:quic Set-Cookie: authed=1;Path=/ X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/servicelogin?service=urlshortener&continue=http://goo.gl/?authed%3d1&followup=http://goo.gl/?authed%3d1&passive=true&go=true | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Mon, 21 Apr 2014 18:52:14 GMT Location: https://accounts.google.com/servicelogin?service=urlshortener&continue=http%3A%2F%2Fgoo.gl%2F%3Fauthed%3D1&followup=http%3A%2F%2Fgoo.gl%2F%3Fauthed%3D1&passive=true&go=true Server: GSE Content-Length: 370 Content-Type: text/html; charset=UTF-8 Expires: Mon, 21 Apr 2014 18:52:14 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/servicelogin?service=urlshortener&continue=http%3a%2f%2fgoo.gl%2f%3fauthed%3d1&followup=http%3a%2f%2fgoo.gl%2f%3fauthed%3d1&passive=true&go=true | HTTP/1.1 200 OK Cache-Control: private, max-age=0 Connection: close Date: Mon, 21 Apr 2014 18:52:14 GMT Server: GSE Content-Length: 1491 Content-Type: text/html; charset=UTF-8 Expires: Mon, 21 Apr 2014 18:52:14 GMT Alternate-Protocol: 443:quic Set-Cookie: GAPS=1:a06yB1zdU3FkwNa3g46YOeBJMyqkNA:t4bnIlHHKa_DLBSy;Path=/;Expires=Wed, 20-Apr-2016 18:52:14 GMT;Secure;HttpOnly Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/& | 404 Not Found Content-Length: 22057 Content-Type: text/html | clean |
https://accounts.google.com/TOS?loc=LT&hl=en | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store Connection: close Date: Mon, 21 Apr 2014 18:52:15 GMT Pragma: no-cache Location: https://www.google.lt/intl/en/policies/terms/ Server: GSE Content-Length: 227 Content-Type: text/html; charset=UTF-8 Expires: Mon, 01-Jan-1990 00:00:00 GMT Alternate-Protocol: 443:quic Set-Cookie: GoogleAccountsLocale_session=en; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/intl/en/policies/terms/ | HTTP/1.1 200 OK Cache-Control: private, max-age=0 Connection: close Date: Mon, 21 Apr 2014 18:52:15 GMT Server: sffe Vary: Accept-Encoding Content-Type: text/html Expires: Mon, 21 Apr 2014 18:52:15 GMT Last-Modified: Tue, 24 Jan 2012 14:44:29 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/intl/en/policies/terms/regional.html | 200 OK Content-Length: 20436 Content-Type: text/html | clean |
https://www.google.lt//www.google.com/js/google.js/ | 404 Not Found Content-Length: 1438 Content-Type: text/html | clean |
https://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1425 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
https://accounts.google.com//www.google.com/js/maia.js/ | 404 Not Found Content-Length: 22057 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.6.1/jquery.min.js | 200 OK Content-Length: 91342 Content-Type: text/javascript | clean |