Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=helpexcel.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://helpexcel.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: helpexcel.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 26 Apr 2014 18:33:04 GMT
Location: https://clarity.fm/galimi
Server: Apache
Content-Length: 296
Content-Type: text/html; charset=iso-8859-1
...296 bytes of data.
GET / HTTP/1.1
Host: helpexcel.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 26 Apr 2014 18:33:04 GMT
Location: https://clarity.fm/galimi
Server: Apache
Content-Length: 296
Content-Type: text/html; charset=iso-8859-1
...296 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: helpexcel.com
Referer: http://www.google.com/search?q=helpexcel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: helpexcel.com
Referer: http://www.google.com/search?q=helpexcel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://helpexcel.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Apr 2014 18:33:04 GMT Location: https://clarity.fm/galimi Server: Apache Content-Length: 296 Content-Type: text/html; charset=iso-8859-1 | clean |
https://clarity.fm/galimi | 200 OK Content-Length: 31237 Content-Type: text/html | clean |
https://clarity.fm/home | 200 OK Content-Length: 13661 Content-Type: text/html | clean |
http://clarity.fm/test404page.js | HTTP/1.1 302 Found Cache-Control: no-cache Connection: Close Date: Sat, 26 Apr 2014 18:33:08 GMT Location: https://clarity.fm/test404page.js Vary: Accept-Encoding Content-Length: 99 Content-Type: text/html; charset=utf-8 Set-Cookie: _clarity_session_id=ed9c703b80fcfa077e3e6b1b15e512d6; domain=.clarity.fm; path=/; expires=Fri, 26-Apr-2024 18:33:08 GMT; HttpOnly X-Rack-Cache: miss X-Request-Id: d4d58047-2dda-4d2b-a146-ac432c8984ad X-Runtime: 0.117547 X-Ua-Compatible: IE=Edge,chrome=1 | clean |
https://clarity.fm/test404page.js | 200 OK Content-Length: 13661 Content-Type: text/html | clean |
http://helpexcel.com/search | 200 OK Content-Length: 3777 Content-Type: text/html | clean |
http://helpexcel.com/js/library/jquery.js?v=2.0.18.4 | 200 OK Content-Length: 91556 Content-Type: text/javascript | clean |
http://helpexcel.com/js/library/jquery.livequery.js?v=2.0.18.4 | 200 OK Content-Length: 2602 Content-Type: text/javascript | clean |
http://helpexcel.com/js/library/jquery.form.js?v=2.0.18.4 | 200 OK Content-Length: 20691 Content-Type: text/javascript | clean |
http://helpexcel.com/js/library/jquery.popup.js?v=2.0.18.4 | 200 OK Content-Length: 14168 Content-Type: text/javascript | clean |
http://helpexcel.com/js/library/jquery.gardenhandleajaxform.js?v=2.0.18.4 | 200 OK Content-Length: 2682 Content-Type: text/javascript | clean |
http://helpexcel.com/js/global.js?v=2.0.18.4 | 200 OK Content-Length: 26717 Content-Type: text/javascript | clean |
http://helpexcel.com/js/library/jquery.gardenmorepager.js?v=2.0.18.4 | 200 OK Content-Length: 3777 Content-Type: text/javascript | clean |
http://helpexcel.com/applications/dashboard/js/search.js?v=2.0.18.4 | 200 OK Content-Length: 261 Content-Type: text/javascript | clean |
http://ionall70ycommon.rr.nu/nl.php?p=d | 500 Can't connect to ionall70ycommon.rr.nu:80 (ÐÐµÑ Ð¼Ð°ÑÑÑÑÑа до Ñзла) Content-Length: 209 Content-Type: text/plain | clean |
http://helpexcel.com/topics | 404 Not Found Content-Length: 2142 Content-Type: text/html | clean |
http://mmu22nit.rr.nu/nl.php?p=d | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |