Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mywebastrologer.com
Result:
HTTP/1.1 200 OK
Date: Wed, 11 Jun 2014 18:40:56 GMT
Accept-Ranges: bytes
ETag: "627f7a3cbecf1:91e27a"
Server: Microsoft-IIS/6.0
Content-Length: 50967
Content-Location: http://mywebastrologer.com/index.html
Content-Type: text/html
Last-Modified: Sat, 11 Jan 2014 12:49:59 GMT
X-Powered-By: ASP.NET
...50967 bytes of data.
GET / HTTP/1.1
Host: mywebastrologer.com
Result:
HTTP/1.1 200 OK
Date: Wed, 11 Jun 2014 18:40:56 GMT
Accept-Ranges: bytes
ETag: "627f7a3cbecf1:91e27a"
Server: Microsoft-IIS/6.0
Content-Length: 50967
Content-Location: http://mywebastrologer.com/index.html
Content-Type: text/html
Last-Modified: Sat, 11 Jan 2014 12:49:59 GMT
X-Powered-By: ASP.NET
...50967 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: mywebastrologer.com
Referer: http://www.google.com/search?q=mywebastrologer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mywebastrologer.com
Referer: http://www.google.com/search?q=mywebastrologer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://mywebastrologer.com/ | HTTP/1.1 200 OK Date: Wed, 11 Jun 2014 18:40:56 GMT Accept-Ranges: bytes ETag: "627f7a3cbecf1:91e27a" Server: Microsoft-IIS/6.0 Content-Length: 50967 Content-Location: http://mywebastrologer.com/index.html Content-Type: text/html Last-Modified: Sat, 11 Jan 2014 12:49:59 GMT X-Powered-By: ASP.NET | clean |
http://mywebastrologer.com/index.html | 200 OK Content-Length: 50967 Content-Type: text/html | clean |
http://www.mywebastrologer.com/images/menu1.js | 200 OK Content-Length: 3098 Content-Type: application/x-javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19942 Content-Type: text/javascript | clean |
http://mywebastrologer.com/gemstore/life-together.aspx | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://mywebastrologer.com/test404page.js | 200 OK Content-Length: 33851 Content-Type: text/html | clean |
http://mywebastrologer.com/images/menu.js | 200 OK Content-Length: 1358 Content-Type: application/x-javascript | clean |
http://mywebastrologer.com/gemstore/vaastu-residential.aspx | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://mywebastrologer.com/gemstore/chosing-career.aspx | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://mywebastrologer.com/gemswear.asp | 200 OK Content-Length: 48557 Content-Type: text/html | clean |
http://mywebastrologer.com/askproff.asp | HTTP/1.1 200 OK Cache-Control: private Date: Wed, 11 Jun 2014 18:41:17 GMT Server: Microsoft-IIS/6.0 Content-Length: 41744 Content-Type: text/html Set-Cookie: ASPSESSIONIDCCBBQTQA=NHEFHAFAMPAIPEKJCNJADFGK; path=/ X-Powered-By: ASP.NET | clean |
http://www.mywebastrologer.com/gemstore/career-report.aspx | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://mywebastrologer.com/gemswear-sample1.asp | 200 OK Content-Length: 42345 Content-Type: text/html | clean |
http://mywebastrologer.com/gemswear-sample2.asp | 200 OK Content-Length: 39424 Content-Type: text/html | clean |
http://mywebastrologer.com/gemstore.asp | HTTP/1.1 200 OK Cache-Control: private Date: Wed, 11 Jun 2014 18:41:25 GMT Server: Microsoft-IIS/6.0 Content-Length: 43361 Content-Type: text/html Set-Cookie: ASPSESSIONIDCCBBQTQA=BIEFHAFACKGHLGOLMBKHCEMP; path=/ X-Powered-By: ASP.NET | clean |
http://www.mywebastrologer.com/gemstone.asp | 200 OK Content-Length: 43925 Content-Type: text/html | clean |
http://www.mywebastrologer.com/images/menu.js | 200 OK Content-Length: 1358 Content-Type: application/x-javascript | clean |
http://mywebastrologer.com/Gem_Healing_about.asp | 200 OK Content-Length: 42363 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mywebastrologer.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://mywebastrologer.com/
Result: mywebastrologer.com is not infected or malware details are not published yet.
Result: mywebastrologer.com is not infected or malware details are not published yet.