Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=profusao.net.br
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://profusao.net.br/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: profusao.net.br
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 25 Feb 2015 07:09:45 GMT
Location: http://www.profusao.net.br/
Server: nginx
Content-Length: 178
Content-Type: text/html
...178 bytes of data.
GET / HTTP/1.1
Host: profusao.net.br
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 25 Feb 2015 07:09:45 GMT
Location: http://www.profusao.net.br/
Server: nginx
Content-Length: 178
Content-Type: text/html
...178 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: profusao.net.br
Referer: http://www.google.com/search?q=profusao.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: profusao.net.br
Referer: http://www.google.com/search?q=profusao.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://profusao.net.br/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 25 Feb 2015 07:09:45 GMT Location: http://www.profusao.net.br/ Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://www.profusao.net.br/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Connection: close Date: Wed, 25 Feb 2015 07:09:45 GMT Pragma: no-cache Via: 1.0 username.wix.com Location: http://www.promeltprofusao.com/ Server: public.app04.tam Content-Language: en Content-Length: 0 Content-Type: text/plain Expires: Thu, 01 Jan 1970 00:00:00 GMT Access-Control-Allow-Origin: * Set-Cookie: hasBeenRedirected=true;Path=/;Domain=.wix.com;Expires=Wed, 25-Feb-2015 07:10:15 GMT X-Seen-By: sputnik01.tam_dsp X-Seen-By: app04.tam-wix public webapp X-Wix-Dispatcher-Cache-Hit: no X-Wix-Redirect-Reason: com.wixpress.dispatch.processors.DomainRedirectDispatchProcessor: Redirecting to primary domain url http://www.promeltprofusao.com/ X-Wix-Redirected-From: http://www.profusao.net.br/ | clean |
http://www.promeltprofusao.com/ | 200 OK Content-Length: 40403 Content-Type: text/html | clean |
http://static.parastorage.com/services/wix-users/2.461.0/client/js/userApi_v2.js?cacheKiller=1 | 200 OK Content-Length: 26761 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/wix-users/2.461.0/user-api/user-api.min.js?cacheKiller=1 | 200 OK Content-Length: 8506 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/core/2.1144.0/javascript/core/utils/mobile_utils.js | 200 OK Content-Length: 12682 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/web/2.1144.0/javascript/wysiwyg/viewer/preloader.js | 200 OK Content-Length: 1675 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/bootstrap/2.1144.0/javascript/bootstrap.min.js | 200 OK Content-Length: 206565 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/web/2.1144.0/deployviewer.min.js | 200 OK Content-Length: 12137 Content-Type: application/x-javascript | clean |
http://static.parastorage.com/services/web/2.1144.0/javascript/wysiwyg/viewer/deprecatedbrowsers/UpgradeBrowser.js | 200 OK Content-Length: 12110 Content-Type: application/x-javascript | clean |
http://profusao.net.br/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 25 Feb 2015 07:09:48 GMT Location: http://www.profusao.net.br/test404page.js Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://www.profusao.net.br/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Connection: close Date: Wed, 25 Feb 2015 07:09:49 GMT Pragma: no-cache Via: 1.0 username.wix.com Location: http://www.promeltprofusao.com/test404page.js Server: public.app28.tam Vary: Accept-Encoding Content-Language: en Content-Length: 0 Content-Type: application/javascript Expires: Thu, 01 Jan 1970 00:00:00 GMT Access-Control-Allow-Origin: * Set-Cookie: hasBeenRedirected=true;Path=/;Domain=.wix.com;Expires=Wed, 25-Feb-2015 07:10:19 GMT X-Seen-By: sputnik02.tam_dsp X-Seen-By: app28.tam-wix public webapp X-Wix-Dispatcher-Cache-Hit: no X-Wix-Redirect-Reason: com.wixpress.dispatch.processors.DomainRedirectDispatchProcessor: Redirecting to primary domain url http://www.promeltprofusao.com/test404page.js X-Wix-Redirected-From: http://www.profusao.net.br/test404page.js | clean |
http://www.promeltprofusao.com/test404page.js | 200 OK Content-Length: 40419 Content-Type: text/html | clean |