Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://larsonhelicopters.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: larsonhelicopters.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sat, 16 May 2015 16:12:59 GMT Location: http://arthytrack2.com/~geosplitter/garcinia/ Server: cloudflare-nginx Content-Type: text/html;charset=UTF-8 CF-RAY: 1e785e049c74169a-ARN Set-Cookie: __cfduid=d48907c71da8f270b94dbd08ec4b91ad51431792778; expires=Sun, 15-May-16 16:12:58 GMT; path=/; domain=.larsonhelicopters.com; HttpOnly | malicious |
URL: http://arthytrack2.com/~geosplitter/garcinia/ (imitation of visitor from search engine) GET /~geosplitter/garcinia/ HTTP/1.1 Host: arthytrack2.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Connection: close Date: Sat, 16 May 2015 16:15:40 GMT Location: http://affiliate.gmtracker.com/rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= Server: Apache/2 Vary: Accept-Encoding,User-Agent Content-Length: 2 Content-Type: text/html X-Powered-By: PHP/5.3.22 | suspicious |
URL: http://affiliate.gmtracker.com/rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= (imitation of visitor from search engine) GET /rd/r.php?sid=1606&pub=301266&c1=&c2=&c3= HTTP/1.1 Host: affiliate.gmtracker.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Found Connection: close Date: Sat, 16 May 2015 16:12:58 GMT Location: https://www.czarlinks.com/api/landing/&pc=958&sid=301266&sid2=733779234 Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 P3P: CP="NOI DSP COR NID CUR OUR STP COM", policyref="/w3c/p3p.xml" Set-Cookie: test=test; expires=Sat, 16-May-2015 16:12:48 GMT Set-Cookie: track=track; expires=Sat, 16-May-2015 16:12:48 GMT Set-Cookie: uid1606=733779234-20150516121258-fda2ef27176ae42c62043e756790765a-0; path=/; domain=.gmtracker.com X-Powered-By: PHP/5.1.6 | suspicious |
URL: https://www.czarlinks.com/api/landing/&pc=958&sid=301266&sid2=733779234 (imitation of visitor from search engine) GET /api/landing/&pc=958&sid=301266&sid2=733779234 HTTP/1.1 Host: www.czarlinks.com Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 16 May 2015 16:13:00 GMT Pragma: no-cache Location: https://secure-my-payments.com/assets9370/garcinia-grass-159ac-ne/?PubID=9&ClickID=72255005&SID=301266&SID2=733779234&LPID=1130&PC=958&Country=lt Server: Apache/2.4.7 (Ubuntu) Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=u4iabdsp25e5iqe7pf51ttu7d3; expires=Sun, 17-May-2015 02:13:00 GMT; Max-Age=36000; path=/ Set-Cookie: ClickCRM255:9:1130=72255005; expires=Sat, 16-May-2015 17:13:00 GMT; Max-Age=3600; path=/; domain=www.phenomcrm.com Set-Cookie: CampaignGroupID=255; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: PublisherID=9; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: LandingPageID=1130; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: SubID=301266; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: SubID2=733779234; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: pc=958; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com Set-Cookie: ClickID=72255005; expires=Wed, 20-May-2015 20:13:00 GMT; Max-Age=360000; path=/; domain=www.phenomcrm.com X-Powered-By: PHP/5.5.9-1ubuntu4.5 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://larsonhelicopters.com/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://larsonhelicopters.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=larsonhelicopters.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://larsonhelicopters.com/
Result: larsonhelicopters.com is not infected or malware details are not published yet.
Result: larsonhelicopters.com is not infected or malware details are not published yet.