Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: isolair.ro
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Tue, 26 Aug 2014 18:21:29 GMT
Pragma: no-cache
Server: nginx/1.4.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3796d8783042650199779a5f05a77885=a736146642c27cee2afb3cb6bee380b5; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: isolair.ro
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Tue, 26 Aug 2014 18:21:29 GMT
Pragma: no-cache
Server: nginx/1.4.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3796d8783042650199779a5f05a77885=a736146642c27cee2afb3cb6bee380b5; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: isolair.ro
Referer: http://www.google.com/search?q=isolair.ro
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: isolair.ro
Referer: http://www.google.com/search?q=isolair.ro
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://isolair.ro/ | 200 OK Content-Length: 28711 Content-Type: text/html | clean |
http://isolair.ro/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://isolair.ro/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://isolair.ro/media/system/js/caption.js | 200 OK Content-Length: 733 Content-Type: application/javascript | clean |
http://isolair.ro/plugins/system/jcemediabox/js/jcemediabox.js?version=114 | 200 OK Content-Length: 55162 Content-Type: application/javascript | clean |
http://isolair.ro/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: application/javascript | clean |
http://isolair.ro/templates/ca_cloudbase2_j25/js/gantry-totop.js | 200 OK Content-Length: 697 Content-Type: application/javascript | clean |
http://isolair.ro/libraries/gantry/js/browser-engines.js | 200 OK Content-Length: 1186 Content-Type: application/javascript | clean |
http://isolair.ro/modules/mod_roknavmenu/themes/fusion/js/fusion.js | 200 OK Content-Length: 25430 Content-Type: application/javascript | clean |
http://isolair.ro/modules/mod_AutsonSlideShow/js/jquery-1.5.2.min.js | 200 OK Content-Length: 85940 Content-Type: application/javascript | clean |
http://isolair.ro/modules/mod_AutsonSlideShow/js/jquery.easing.1.3.js | 200 OK Content-Length: 8301 Content-Type: application/javascript | clean |
http://isolair.ro/modules/mod_AutsonSlideShow/js/jquery.animate-colors-min.js | 200 OK Content-Length: 1745 Content-Type: application/javascript | clean |
http://isolair.ro/modules/mod_AutsonSlideShow/js/jquery.skitter.min.js | 200 OK Content-Length: 50255 Content-Type: application/javascript | clean |
http://isolair.ro/index.php?option=com_content&view=article&id=2&Itemid=124 | 200 OK Content-Length: 30705 Content-Type: text/html | clean |
http://isolair.ro/index.php?option=com_content&view=article&id=53&Itemid=126 | 200 OK Content-Length: 37410 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=isolair.ro
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://isolair.ro/
Result: isolair.ro is not infected or malware details are not published yet.
Result: isolair.ro is not infected or malware details are not published yet.