Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: nanoyou.eu
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 12 Sep 2014 23:39:21 GMT
Pragma: no-cache
Server: Apache/2.2.16 (Debian)
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Fri, 12 Sep 2014 23:39:22 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: da2504779aedbc4f2ee2a8ad67e90412=co61hj4blihbjl66dham35no84; path=/
Set-Cookie: lang=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
Set-Cookie: jfcookie=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
Set-Cookie: jfcookie[lang]=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
GET / HTTP/1.1
Host: nanoyou.eu
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 12 Sep 2014 23:39:21 GMT
Pragma: no-cache
Server: Apache/2.2.16 (Debian)
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Fri, 12 Sep 2014 23:39:22 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: da2504779aedbc4f2ee2a8ad67e90412=co61hj4blihbjl66dham35no84; path=/
Set-Cookie: lang=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
Set-Cookie: jfcookie=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
Set-Cookie: jfcookie[lang]=deleted; expires=Thu, 12-Sep-2013 23:39:20 GMT; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: nanoyou.eu
Referer: http://www.google.com/search?q=nanoyou.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: nanoyou.eu
Referer: http://www.google.com/search?q=nanoyou.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.nanoyou.eu/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:21 GMT Location: http://nanoyou.eu/ Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 306 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/ | 200 OK Content-Length: 54668 Content-Type: text/html | clean |
http://nanoyou.eu/plugins/system/jceutilities/js/mediaobject.js?v=224 | 200 OK Content-Length: 3733 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/system/jceutilities/js/jceutilities.js?v=224 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:22 GMT Location: http://nanoyou.eu/plugins/system/jceutilities/js/jceutilities.js?v=224 Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 358 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/system/jceutilities/js/jceutilities.js?v=224 | 200 OK Content-Length: 27822 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/components/com_jcomments/js/jcomments-v2.1.js?v=2 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:23 GMT Location: http://nanoyou.eu/components/com_jcomments/js/jcomments-v2.1.js?v=2 Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 355 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/components/com_jcomments/js/jcomments-v2.1.js?v=2 | 200 OK Content-Length: 26830 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/components/com_jcomments/libraries/joomlatune/ajax.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:23 GMT Location: http://nanoyou.eu/components/com_jcomments/libraries/joomlatune/ajax.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 359 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/components/com_jcomments/libraries/joomlatune/ajax.js | 200 OK Content-Length: 3990 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/media/system/js/caption.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:24 GMT Location: http://nanoyou.eu/media/system/js/caption.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 332 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/content/avreloaded/silverlight.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:24 GMT Location: http://nanoyou.eu/plugins/content/avreloaded/silverlight.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 347 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/content/avreloaded/silverlight.js | 200 OK Content-Length: 8105 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/content/avreloaded/wmvplayer.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:25 GMT Location: http://nanoyou.eu/plugins/content/avreloaded/wmvplayer.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 345 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/content/avreloaded/wmvplayer.js | 200 OK Content-Length: 16488 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/content/avreloaded/swfobject.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:25 GMT Location: http://nanoyou.eu/plugins/content/avreloaded/swfobject.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 345 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/content/avreloaded/swfobject.js | 200 OK Content-Length: 12266 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/content/avreloaded/avreloaded.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:26 GMT Location: http://nanoyou.eu/plugins/content/avreloaded/avreloaded.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 346 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/content/avreloaded/avreloaded.js | 200 OK Content-Length: 2371 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/media/system/js/modal.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:27 GMT Location: http://nanoyou.eu/media/system/js/modal.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 330 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/media/system/js/modal.js | 200 OK Content-Length: 10588 Content-Type: application/javascript | clean |
http://nanoyou.eu/modules/mod_news_show_gk3/scripts/engine_1_11_compressed.js | 200 OK Content-Length: 1571 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/modules/mod_rokstories/tmpl/js/rokstories.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:28 GMT Location: http://nanoyou.eu/modules/mod_rokstories/tmpl/js/rokstories.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 350 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/modules/mod_rokstories/tmpl/js/rokstories.js | 200 OK Content-Length: 5598 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/system/rokbox/rokbox.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:28 GMT Location: http://nanoyou.eu/plugins/system/rokbox/rokbox.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 337 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 20288 Content-Type: application/javascript | clean |
http://www.nanoyou.eu/plugins/system/rokbox/themes/light/rokbox-config.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 23:39:29 GMT Location: http://nanoyou.eu/plugins/system/rokbox/themes/light/rokbox-config.js Server: Apache/2.2.16 (Debian) Vary: Accept-Encoding Content-Length: 357 Content-Type: text/html; charset=iso-8859-1 | clean |
http://nanoyou.eu/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2697 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=nanoyou.eu
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://nanoyou.eu/
Result: nanoyou.eu is not infected or malware details are not published yet.
Result: nanoyou.eu is not infected or malware details are not published yet.