Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: prescottaudubon.org
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Mon, 23 Jun 2014 05:03:15 GMT
Accept-Ranges: bytes
Server: nginx/1.6.0
Vary: Accept-Encoding,Cookie
Content-Length: 38507
Content-Type: text/html; charset=UTF-8
Expires: Mon, 23 Jun 2014 05:03:18 GMT
Last-Modified: Sat, 21 Jun 2014 20:14:31 GMT
...38507 bytes of data.
GET / HTTP/1.1
Host: prescottaudubon.org
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Mon, 23 Jun 2014 05:03:15 GMT
Accept-Ranges: bytes
Server: nginx/1.6.0
Vary: Accept-Encoding,Cookie
Content-Length: 38507
Content-Type: text/html; charset=UTF-8
Expires: Mon, 23 Jun 2014 05:03:18 GMT
Last-Modified: Sat, 21 Jun 2014 20:14:31 GMT
...38507 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: prescottaudubon.org
Referer: http://www.google.com/search?q=prescottaudubon.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: prescottaudubon.org
Referer: http://www.google.com/search?q=prescottaudubon.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://prescottaudubon.org/ | 200 OK Content-Length: 38507 Content-Type: text/html | clean |
http://prescottaudubon.org/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/flex-feature-slider/js/jquery.cycle.all.min.js?ver=3.9.1 | 200 OK Content-Length: 31032 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/themes/flexsqueeze150/js/flexscripts.js?ver=3.9.1 | 200 OK Content-Length: 4777 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/wp-cart-for-digital-products/lib/jquery.external.lib.js?ver=3.9.1 | 200 OK Content-Length: 2318 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/wp-cart-for-digital-products/lib/jquery.lightbox-0.5.pack.js?ver=3.9.1 | 200 OK Content-Length: 7229 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/responsive-lightbox/assets/swipebox/source/jquery.swipebox.min.js?ver=3.9.1 | 200 OK Content-Length: 9594 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/responsive-lightbox/js/front.js?ver=3.9.1 | 200 OK Content-Length: 4841 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/countdown-timer/js/webtoolkit.sprintf.js?ver=3.0.6 | 200 OK Content-Length: 2148 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/kswp_pop_wizard/js/cluetip/jquery.cluetip.js?ver=2019599000 | 200 OK Content-Length: 23937 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/kswp_pop_wizard/js/jquery.kswppw_tips?ver=1757640757 | 200 OK Content-Length: 4214 Content-Type: text/html | clean |
http://prescottaudubon.org/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 23 Jun 2014 05:03:24 GMT Pragma: no-cache Location: http://prescottaudubon.org Server: nginx/1.6.0 Vary: Cookie Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=c2db14dfc9b7b849c80d31515f0b5b51; path=/ X-Pingback: http://prescottaudubon.org/xmlrpc.php | clean |
http://prescottaudubon.org/wp-content/plugins/wp-cart-for-digital-products/lib/eStore_read_form.js | 200 OK Content-Length: 5788 Content-Type: application/javascript | clean |
http://prescottaudubon.org/wp-content/plugins/no-right-click-images-plugin/no-right-click-images.js | 200 OK Content-Length: 7337 Content-Type: application/javascript | clean |
http://www.statcounter.com/counter/counter_xhtml.js | 200 OK Content-Length: 9028 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=prescottaudubon.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://prescottaudubon.org/
Result: prescottaudubon.org is not infected or malware details are not published yet.
Result: prescottaudubon.org is not infected or malware details are not published yet.