Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: myhome.com.tr
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=315360000
Connection: close
Date: Mon, 26 Jan 2015 21:45:09 GMT
Accept-Ranges: bytes
ETag: "86387-9b2c-50b865e87945b"
Server: nginx
Content-Length: 39724
Content-Type: text/html
Expires: Thu, 23 Jan 2025 21:45:09 GMT
Last-Modified: Wed, 31 Dec 2014 17:23:43 GMT
X-Powered-By: PleskLin
...39724 bytes of data.
GET / HTTP/1.1
Host: myhome.com.tr
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=315360000
Connection: close
Date: Mon, 26 Jan 2015 21:45:09 GMT
Accept-Ranges: bytes
ETag: "86387-9b2c-50b865e87945b"
Server: nginx
Content-Length: 39724
Content-Type: text/html
Expires: Thu, 23 Jan 2025 21:45:09 GMT
Last-Modified: Wed, 31 Dec 2014 17:23:43 GMT
X-Powered-By: PleskLin
...39724 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: myhome.com.tr
Referer: http://www.google.com/search?q=myhome.com.tr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: myhome.com.tr
Referer: http://www.google.com/search?q=myhome.com.tr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.myhome.com.tr/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 26 Jan 2015 21:45:09 GMT Location: http://myhome.com.tr/ Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://myhome.com.tr/ | 200 OK Content-Length: 39724 Content-Type: text/html | clean |
http://myhome.com.tr/wp-includes/js/jquery/jquery.js | 200 OK Content-Length: 95807 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-includes/js/jquery/jquery-migrate.min.js | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://cdnjs.cloudflare.com/ajax/libs/modernizr/2.6.2/modernizr.min.js | 200 OK Content-Length: 15414 Content-Type: application/javascript | clean |
http://myhome.com.tr/wp-includes/js/comment-reply.min.js | 200 OK Content-Length: 757 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/sliders/iosslider/jquery.iosslider.min.js | 200 OK Content-Length: 30082 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/sliders/iosslider/jquery.iosslider.kalypso.js | 200 OK Content-Length: 5697 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/js/bootstrap.min.js | 200 OK Content-Length: 11086 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/js/plugins.js | 200 OK Content-Length: 10136 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/addons/superfish_responsive/superfish_menu.js | 200 OK Content-Length: 8590 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/addons/prettyphoto/jquery.prettyPhoto.js | 200 OK Content-Length: 25341 Content-Type: text/javascript | clean |
http://myhome.com.tr/wp-content/themes/myhomehali/js/znscript.js | 200 OK Content-Length: 11764 Content-Type: text/javascript | clean |
http://www.myhome.com.tr/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 26 Jan 2015 21:45:14 GMT Location: http://myhome.com.tr/test404page.js Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://myhome.com.tr/test404page.js | 404 Not Found Content-Length: 27494 Content-Type: text/html | clean |
http://myhome.com.tr/kurumsal/ | 200 OK Content-Length: 28657 Content-Type: text/html | clean |
http://myhome.com.tr/portfolio/ | 200 OK Content-Length: 41788 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=myhome.com.tr
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://myhome.com.tr/
Result: myhome.com.tr is not infected or malware details are not published yet.
Result: myhome.com.tr is not infected or malware details are not published yet.