Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://perfumnania.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: perfumnania.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Date: Sat, 12 Apr 2014 10:29:11 GMT Location: http://www.kqzyfj.com/click-2798135-6674831?sid=perfumnania%2Ecom Content-Length: 0 | malicious |
URL: http://www.kqzyfj.com/click-2798135-6674831?sid=perfumnania%2Ecom (imitation of visitor from search engine) GET /click-2798135-6674831?sid=perfumnania%2Ecom HTTP/1.1 Host: www.kqzyfj.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 12 Apr 2014 10:29:11 GMT Pragma: no-cache Location: http://cj.dotomi.com/pq80qgpo6/gns/AAB8C75/6BDC579/4/4/4?e=l3to%3D0p2q5xylytl.nzx<<s440%3A%2F%2F777.v1A9qu.nzx%3AJB%2Fnwtnv-DIKJCEG-HHIFJEC<<R<s440%3A%2F%2F777.rzzrwp.nzx%2F52w%3F3l%3D4%262n4%3Du%261%3D0p2q5xylytl.nzx%263z52np%3D7pm%26no%3DC%266po%3DBNOPbQuLR%2652w%3Ds440%3A%25DQ%25DQ0p2q5xylytl.nzx%25DQ%26pt%3D7NI9eG1NUmNNvbV4y7P%2653r%3DLQbuNYRPpj0EOI55YWLU8XTgwtW9bKZ_ar< Server: Resin/3.1.8 Content-Type: text/html Expires: Sat, 12 Apr 2014 10:29:11 GMT P3P: policyref="/w3c/p3p.xml", CP="ALL BUS LEG DSP COR ADM CUR DEV PSA OUR NAV INT" | suspicious |
URL: http://cj.dotomi.com/pq80qgpo6/gns/AAB8C75/6BDC579/4/4/4?e=l3to%3D0p2q5xylytl.nzx< GET /pq80qgpo6/gns/AAB8C75/6BDC579/4/4/4?e=l3to%3D0p2q5xylytl.nzx< Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 12 Apr 2014 10:29:11 GMT Pragma: no-cache Location: http://www.emjcd.com/r5121js0-K/sz3/MMNKOJH/INPOHJL/G/KGGJGGKGNJKMNLNPKI/KPtqvPKPsIItHHuJOGOILsIMGqvuGvtu?p=pG61%3DD2F3IAByB6y.0CA<07C!72PI-4OP38NR<5HHD%3A%2F%2FKKK.8ENM37.0CA%3AWO%2F09608-QVXWPRT-UUVSWRP<<e<5HHD%3A%2F%2FKKK.4CC492.0CA%2FIF9%3FGy%3DH%26F0H%3D7%26E%3DD2F3IAByB6y.0CA%26GCIF02%3DK2z%2601%3DP%26J21%3DOabcod7Ye%26IF9%3D5HHD%3A%25Qd%25QdD2F3IAByB6y.0CA%25Qd%2626%3DKaVMrTEahzaa8oiHBKc%26IG4%3DYdo7alec2wDRbVIIljYhLkgt96jMoXm_n4< Server: Resin/3.1.8 Content-Type: text/html Expires: Sat, 12 Apr 2014 10:29:11 GMT P3P: policyref="/w3c/p3p-d.xml", CP="NOI DSP NID OUR STP" Set-Cookie: S=400300407346757942; domain=.dotomi.com; path=/; expires=Mon, 11-Apr-2016 10:29:04 GMT Set-Cookie: LCLK=cjo!je1u-g01fkz3; domain=.dotomi.com; path=/; expires=Mon, 11-Apr-2016 10:29:04 GMT | suspicious |
URL: http://www.emjcd.com/r5121js0-K/sz3/MMNKOJH/INPOHJL/G/KGGJGGKGNJKMNLNPKI/KPtqvPKPsIItHHuJOGOILsIMGqvuGvtu?p=pG61%3DD2F3IAByB6y.0CA<07C!72PI-4OP38NR<5HHD%3A%2F%2FKKK.8ENM37.0CA%3AWO%2F09608-QVXWPRT-UUVSWRP< GET /r5121js0-K/sz3/MMNKOJH/INPOHJL/G/KGGJGGKGNJKMNLNPKI/KPtqvPKPsIItHHuJOGOILsIMGqvuGvtu?p=pG61%3DD2F3IAByB6y.0CA<07C!72PI-4OP38NR<5HHD%3A%2F%2FKKK.8ENM37.0CA%3AWO%2F09608-QVXWPRT-UUVSWRP< Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 12 Apr 2014 10:29:11 GMT Pragma: no-cache Location: http://www.perfumania.com/perftracker.aspx?AID=6674831&PID=2798135&SID=perfumnania.com&utm_source=CommissionJunction&utm_medium=Affiliate Server: Resin/3.1.8 Content-Type: text/html Expires: Sat, 12 Apr 2014 10:29:12 GMT P3P: policyref="/w3c/p3p.xml", CP="ALL BUS LEG DSP COR ADM CUR DEV PSA OUR NAV INT" Set-Cookie: S=400300407346757942; domain=.emjcd.com; path=/; expires=Mon, 11-Apr-2016 10:29:04 GMT Set-Cookie: LCLK=cjo!je1u-g01fkz3; domain=.emjcd.com; path=/; expires=Mon, 11-Apr-2016 10:29:04 GMT | suspicious |
Scanned pages/files
Request | Server response | Status |
http://perfumnania.com/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://perfumnania.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=perfumnania.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://perfumnania.com/
Result: perfumnania.com is not infected or malware details are not published yet.
Result: perfumnania.com is not infected or malware details are not published yet.