Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.newsofwww.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.newsofwww.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Fri, 25 Dec 2015 10:42:36 GMT Location: http://track.trustmarketcom.com/d10b5d83-227c-4cb1-a8ff-ce7a96926660?c=n_30710_2 Server: cloudflare-nginx Content-Type: text/html;charset=UTF-8 CF-RAY: 25a3f0b25d852afd-WAW Set-Cookie: __cfduid=d135fe076e999e23d2418dab63db5c3ae1451040156; expires=Sat, 24-Dec-16 10:42:36 GMT; path=/; domain=.newsofwww.com; HttpOnly | malicious |
URL: http://track.trustmarketcom.com/d10b5d83-227c-4cb1-a8ff-ce7a96926660?c=n_30710_2 (imitation of visitor from search engine) GET /d10b5d83-227c-4cb1-a8ff-ce7a96926660?c=n_30710_2 HTTP/1.1 Host: track.trustmarketcom.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, pre-check=0, post-check=0 Connection: Close Date: Fri, 25 Dec 2015 10:42:37 GMT Pragma: no-cache Location: http://advidi.optimuum.com/f77d28ba2e956a1c/cd?aff_id=1727&s1=d10b5d83-227c-4cb1-a8ff-ce7a96926660&s2=w9VHIAQC2T6QFAGPGQG453HG&s3=n_30710_2&s4= Server: Voluum-Traffic/1.0 Content-Length: 0 Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: d10b5d83-227c-4cb1-a8ff-ce7a96926660-v4=d10b5d83-227c-4cb1-a8ff-ce7a96926660; Domain=track.trustmarketcom.com; Path=/; HttpOnly Set-Cookie: voluum-cid-v4=%7B%0A%20%20%22cid%22%20%3A%20%22w9VHIAQC2T6QFAGPGQG453HG%22%2C%0A%20%20%22caid%22%20%3A%20%22d10b5d83-227c-4cb1-a8ff-ce7a96926660%22%0A%7D; Domain=track.trustmarketcom.com; Expires=Sat, 24-Dec-2016 10:42:37 GMT; Path=/; HttpOnly X-Robots-Tag: noindex, nofollow | malicious |
URL: http://advidi.optimuum.com/f77d28ba2e956a1c/cd?aff_id=1727&s1=d10b5d83-227c-4cb1-a8ff-ce7a96926660&s2=w9VHIAQC2T6QFAGPGQG453HG&s3=n_30710_2&s4= (imitation of visitor from search engine) GET /f77d28ba2e956a1c/cd?aff_id=1727&s1=d10b5d83-227c-4cb1-a8ff-ce7a96926660&s2=w9VHIAQC2T6QFAGPGQG453HG&s3=n_30710_2&s4= HTTP/1.1 Host: advidi.optimuum.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 25 Dec 2015 10:42:37 GMT Location: http://stuntoffer.com/?limited_offer=R33Q12U19i4f4g131GnLc&bg=bg4&exit_block_type=noescape2&url=%5Bhttp%3A%2F%2Fadvidi.optimuum.com%2Fcb%2Fcb68a32a61c1c4e3%2F12a2eb46e662f76e18a4e9bf2dd20a2b%5D Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html;charset=utf-8 Set-Cookie: cb68a32a61c1c4e3=%5B%5B120%5D%2C%5B2570%5D%2C%5B20299%5D%5D; max-age=2592000 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Who: redirects-front-euw1b X-XSS-Protection: 1; mode=block | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.newsofwww.com/ | 403 Forbidden Content-Length: 155 Content-Type: text/html | clean |
http://www.newsofwww.com/test404page.js | 403 Forbidden Content-Length: 155 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=newsofwww.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://newsofwww.com/
Result: newsofwww.com is not infected or malware details are not published yet.
Result: newsofwww.com is not infected or malware details are not published yet.