Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.indpendentprofessionalbaseballfederation.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.indpendentprofessionalbaseballfederation.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Wed, 03 Jun 2015 05:59:01 GMT Location: http://arthytrack2.com/~geosplitter/garcinia/ Server: cloudflare-nginx Content-Type: text/html;charset=UTF-8 CF-RAY: 1f092b6b9f5405bb-ARN Set-Cookie: __cfduid=dcd85e195632d3cf9fb4d7e93eed6a4ed1433311141; expires=Thu, 02-Jun-16 05:59:01 GMT; path=/; domain=.indpendentprofessionalbaseballfederation.com; HttpOnly | malicious |
URL: http://arthytrack2.com/~geosplitter/garcinia/ (imitation of visitor from search engine) GET /~geosplitter/garcinia/ HTTP/1.1 Host: arthytrack2.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Connection: close Date: Wed, 03 Jun 2015 06:03:34 GMT Location: http://affiliate.gmtracker.com/rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= Server: Apache/2 Vary: Accept-Encoding,User-Agent Content-Length: 2 Content-Type: text/html X-Powered-By: PHP/5.3.22 | suspicious |
URL: http://affiliate.gmtracker.com/rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= (imitation of visitor from search engine) GET /rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= HTTP/1.1 Host: affiliate.gmtracker.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Found Connection: close Date: Wed, 03 Jun 2015 05:59:01 GMT Location: https://www.partnermedia.biz/api/landing/&pc=958&sid=301266&sid2=733997776 Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 P3P: CP="NOI DSP COR NID CUR OUR STP COM", policyref="/w3c/p3p.xml" Set-Cookie: test=test; expires=Wed, 03-Jun-2015 05:58:51 GMT Set-Cookie: track=track; expires=Wed, 03-Jun-2015 05:58:51 GMT Set-Cookie: uid1606=733997776-20150603015901-fda2ef27176ae42c62043e756790765a-0; path=/; domain=.gmtracker.com X-Powered-By: PHP/5.1.6 | suspicious |
URL: https://www.partnermedia.biz/api/landing/&pc=958&sid=301266&sid2=733997776 (imitation of visitor from search engine) GET /api/landing/&pc=958&sid=301266&sid2=733997776 HTTP/1.1 Host: www.partnermedia.biz Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 03 Jun 2015 05:59:03 GMT Pragma: no-cache Location: https://secure-my-payments.com/assets9649/garcinia-grass-159ac-ne/?PubID=9&ClickID=73371784&SID=301266&SID2=733997776&LPID=1130&PC=958&Country=lt Server: Apache/2.4.7 (Ubuntu) Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=l9ig7nth690nlbqcrhejuurpl7; expires=Wed, 03-Jun-2015 15:59:03 GMT; Max-Age=36000; path=/ Set-Cookie: ClickCRM255:9:1130=73371784; expires=Wed, 03-Jun-2015 06:59:03 GMT; Max-Age=3600; path=/; domain=www.phenomcrm.com Set-Cookie: CampaignGroupID=255; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: PublisherID=9; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: LandingPageID=1130; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: SubID=301266; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: SubID2=733997776; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: pc=958; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: ClickID=73371784; expires=Sun, 07-Jun-2015 09:59:03 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com X-Powered-By: PHP/5.5.9-1ubuntu4.5 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.indpendentprofessionalbaseballfederation.com/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.indpendentprofessionalbaseballfederation.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=indpendentprofessionalbaseballfederation.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://indpendentprofessionalbaseballfederation.com/
Result: indpendentprofessionalbaseballfederation.com is not infected or malware details are not published yet.
Result: indpendentprofessionalbaseballfederation.com is not infected or malware details are not published yet.