Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mrsworldroyalty.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mblausteinfurs.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Tue, 03 Mar 2015 00:39:10 GMT
Location: http://mblaustein.com/
Server: AmazonS3
Content-Length: 0
X-Amz-Id-2: 36sH5i1XUX0XuMA7m3LnRsTt6TEsfw3BTffLEokSZ9YmsEVB/UaBbacaW6KsXypv7+cj7j1o9yE=
X-Amz-Request-Id: 553896AE077F512A
...0 bytes of data.
GET / HTTP/1.1
Host: mblausteinfurs.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Tue, 03 Mar 2015 00:39:10 GMT
Location: http://mblaustein.com/
Server: AmazonS3
Content-Length: 0
X-Amz-Id-2: 36sH5i1XUX0XuMA7m3LnRsTt6TEsfw3BTffLEokSZ9YmsEVB/UaBbacaW6KsXypv7+cj7j1o9yE=
X-Amz-Request-Id: 553896AE077F512A
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: mblausteinfurs.com
Referer: http://www.google.com/search?q=mblausteinfurs.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mblausteinfurs.com
Referer: http://www.google.com/search?q=mblausteinfurs.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://mrsworldroyalty.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Wed, 04 Mar 2015 00:31:08 GMT Age: 0 Location: http://americaroyalty.com Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://americaroyalty.com/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://americaroyalty.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |