Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: natas.co.uk
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 13 Apr 2015 14:41:21 GMT
Accept-Ranges: bytes
Location: http://www.natas.co.uk/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Host-Header: 192fc2e7e50945beb8231a492d6a8024
X-Cache: SGCACHE-MISS
X-Forwarded-For: 78.158.11.226
X-Pingback: http://www.natas.co.uk/xmlrpc.php
...0 bytes of data.
GET / HTTP/1.1
Host: natas.co.uk
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 13 Apr 2015 14:41:21 GMT
Accept-Ranges: bytes
Location: http://www.natas.co.uk/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Host-Header: 192fc2e7e50945beb8231a492d6a8024
X-Cache: SGCACHE-MISS
X-Forwarded-For: 78.158.11.226
X-Pingback: http://www.natas.co.uk/xmlrpc.php
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: natas.co.uk
Referer: http://www.google.com/search?q=natas.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: natas.co.uk
Referer: http://www.google.com/search?q=natas.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://natas.co.uk/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 13 Apr 2015 14:41:21 GMT Accept-Ranges: bytes Location: http://www.natas.co.uk/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Host-Header: 192fc2e7e50945beb8231a492d6a8024 X-Cache: SGCACHE-MISS X-Forwarded-For: 78.158.11.226 X-Pingback: http://www.natas.co.uk/xmlrpc.php | clean |
http://www.natas.co.uk/ | 200 OK Content-Length: 37634 Content-Type: text/html | clean |
http://www.natas.co.uk/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.plugins.min.js?rev=4.0.5&ver=4.0.1 | 200 OK Content-Length: 64381 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?rev=4.0.5&ver=4.0.1 | 200 OK Content-Length: 71799 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/jquery.preloadify.min.js?ver=1.0 | 200 OK Content-Length: 1512 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/superfish.js?ver=1.0 | 200 OK Content-Length: 3714 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/jquery.mobilemenu.js?ver=1.0 | 200 OK Content-Length: 1751 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/custom.js?ver=1.4.8 | 200 OK Content-Length: 15089 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/html5shim.js?ver=4.0.1 | 200 OK Content-Length: 2428 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/plugins/no-right-click-images-plugin/no-right-click-images.js | 200 OK Content-Length: 7381 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20 | 200 OK Content-Length: 15248 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=4.0.1 | 200 OK Content-Length: 9658 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/hoverIntent.js?ver=6.0 | 200 OK Content-Length: 5195 Content-Type: application/javascript | clean |
http://www.natas.co.uk/wp-content/themes/sympathique/js/jflickrfeed.js?ver=1.0 | 200 OK Content-Length: 2330 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=natas.co.uk
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://natas.co.uk/
Result: natas.co.uk is not infected or malware details are not published yet.
Result: natas.co.uk is not infected or malware details are not published yet.