Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hiredgoons.ca
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 30 Sep 2014 19:13:30 GMT
Pragma: no-cache
Server: LiteSpeed
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=5676fd6ccfa579aae8f1eb714a2857c9; path=/
X-Powered-By: PHP/5.3.28
GET / HTTP/1.1
Host: hiredgoons.ca
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 30 Sep 2014 19:13:30 GMT
Pragma: no-cache
Server: LiteSpeed
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=5676fd6ccfa579aae8f1eb714a2857c9; path=/
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: hiredgoons.ca
Referer: http://www.google.com/search?q=hiredgoons.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hiredgoons.ca
Referer: http://www.google.com/search?q=hiredgoons.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://hiredgoons.ca/ | 200 OK Content-Length: 48531 Content-Type: text/html | clean |
http://hiredgoons.ca/quotes.php | 200 OK Content-Length: 8700 Content-Type: text/html | clean |
http://hiredgoons.ca/timers.php | 200 OK Content-Length: 8435 Content-Type: text/html | clean |
http://hiredgoons.ca/index.php | 200 OK Content-Length: 48509 Content-Type: text/html | clean |
http://hiredgoons.ca/aboutme.php | 200 OK Content-Length: 8777 Content-Type: text/html | clean |
http://hiredgoons.ca/software/ | 200 OK Content-Length: 9183 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/ | 200 OK Content-Length: 11093 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/buildCalc.exe | 200 OK Content-Length: 65536 Content-Type: application/x-msdownload | clean |
http://hiredgoons.ca/test404page.js | 404 Not Found Content-Length: 1148 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/changelog.php | 200 OK Content-Length: 10191 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/./ | 200 OK Content-Length: 11031 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/./buildCalc.exe | 200 OK Content-Length: 65536 Content-Type: application/x-msdownload | clean |
http://hiredgoons.ca/software/./buildcalc/./changelog.php | 200 OK Content-Length: 10166 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/././ | 200 OK Content-Length: 11275 Content-Type: text/html | clean |
http://hiredgoons.ca/software/./buildcalc/././buildCalc.exe | 200 OK Content-Length: 65536 Content-Type: application/x-msdownload | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hiredgoons.ca
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hiredgoons.ca/
Result: hiredgoons.ca is not infected or malware details are not published yet.
Result: hiredgoons.ca is not infected or malware details are not published yet.