Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: msquaredlaw.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 23 Jul 2014 17:08:17 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=0tc54u09vnrrpd92gkp9uv6ag0; path=/
Set-Cookie: _icl_current_language=en; expires=Thu, 24-Jul-2014 17:08:19 GMT; path=/
X-Pingback: http://msquaredlaw.com/xmlrpc.php
GET / HTTP/1.1
Host: msquaredlaw.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 23 Jul 2014 17:08:17 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=0tc54u09vnrrpd92gkp9uv6ag0; path=/
Set-Cookie: _icl_current_language=en; expires=Thu, 24-Jul-2014 17:08:19 GMT; path=/
X-Pingback: http://msquaredlaw.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: msquaredlaw.com
Referer: http://www.google.com/search?q=msquaredlaw.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: msquaredlaw.com
Referer: http://www.google.com/search?q=msquaredlaw.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://msquaredlaw.com/ | 200 OK Content-Length: 19813 Content-Type: text/html | clean |
http://msquaredlaw.com/wp-includes/js/jquery/jquery.js?ver=1.8.3 | 200 OK Content-Length: 93658 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/plugins/nmedia-mailchimp-widget/js/ajax.js?ver=3.5.1 | 200 OK Content-Length: 3063 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/sliders/cycle/jquery.cycle.all.min.js?ver=2.86 | 200 OK Content-Length: 30320 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/sliders/cycle/cycle1/cycle1_script.js?ver=1.0.0 | 200 OK Content-Length: 1115 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/scripts/prettyPhoto/js/jquery.prettyPhoto.js?ver=3.1.3 | 200 OK Content-Length: 24867 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/scripts/superfish-1.4.8/js/superfish.combined.js?ver=1.0.0 | 200 OK Content-Length: 5387 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/scripts/script.js?ver=1.0 | 200 OK Content-Length: 7254 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/plugins/sitepress-multilingual-cms/res/js/sitepress.js | 200 OK Content-Length: 994 Content-Type: application/javascript | clean |
http://msquaredlaw.com//use.typekit.net/mtu1xmh.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Wed, 23 Jul 2014 17:08:27 GMT Pragma: no-cache Location: http://msquaredlaw.com/use.typekit.net/mtu1xmh.js/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=0mok2a315dme6j3o2nt135g6f0; path=/ X-Pingback: http://msquaredlaw.com/xmlrpc.php | clean |
http://msquaredlaw.com/use.typekit.net/mtu1xmh.js/ | 404 Not Found Content-Length: 19109 Content-Type: text/html | clean |
http://msquaredlaw.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.32.0-2013.04.03 | 200 OK Content-Length: 15479 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.4 | 200 OK Content-Length: 6985 Content-Type: application/javascript | clean |
http://msquaredlaw.com/wp-content/themes/purevision/scripts/prettyPhoto/custom_params.js?ver=3.1.3 | 200 OK Content-Length: 7985 Content-Type: application/javascript | clean |
http://msquaredlaw.com/es/ | 200 OK Content-Length: 19766 Content-Type: text/html | clean |
http://msquaredlaw.com/fr/ | 200 OK Content-Length: 19776 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=msquaredlaw.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://msquaredlaw.com/
Result: msquaredlaw.com is not infected or malware details are not published yet.
Result: msquaredlaw.com is not infected or malware details are not published yet.