Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: punjabitribuneonline.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=300, must-revalidate, public
Connection: close
Date: Fri, 10 Oct 2014 16:54:09 GMT
Accept-Ranges: bytes
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding,Cookie
Content-Length: 120027
Content-Type: text/html; charset=UTF-8
Expires: Fri, 10 Oct 2014 16:59:09 GMT
Last-Modified: Fri, 10 Oct 2014 16:54:06 GMT
...120027 bytes of data.
GET / HTTP/1.1
Host: punjabitribuneonline.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=300, must-revalidate, public
Connection: close
Date: Fri, 10 Oct 2014 16:54:09 GMT
Accept-Ranges: bytes
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding,Cookie
Content-Length: 120027
Content-Type: text/html; charset=UTF-8
Expires: Fri, 10 Oct 2014 16:59:09 GMT
Last-Modified: Fri, 10 Oct 2014 16:54:06 GMT
...120027 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: punjabitribuneonline.com
Referer: http://www.google.com/search?q=punjabitribuneonline.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: punjabitribuneonline.com
Referer: http://www.google.com/search?q=punjabitribuneonline.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.punjabitribuneonline.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=7200, public Connection: close Date: Fri, 10 Oct 2014 16:54:06 GMT Location: http://punjabitribuneonline.com/ Server: Apache/2.2.22 (Ubuntu) Vary: Cookie,Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Fri, 10 Oct 2014 18:54:06 GMT X-Pingback: http://punjabitribuneonline.com/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.9 | clean |
http://punjabitribuneonline.com/ | 200 OK Content-Length: 120027 Content-Type: text/html | clean |
http://www.google.com/jsapi | 200 OK Content-Length: 24552 Content-Type: text/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/themes/punjabinew/js/jquery-1.6.js?ver=1332926593 | 200 OK Content-Length: 133489 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-includes/js/jquery/jquery.js?ver=1.7.1 | 200 OK Content-Length: 93889 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/plugins/smooth-slider/js/stepcarousel.js?ver=2.2 | 200 OK Content-Length: 15724 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-includes/js/swfobject.js?ver=2.2 | 200 OK Content-Length: 10220 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.3 | 200 OK Content-Length: 10263 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995 | 200 OK Content-Length: 26590 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.05 | 200 OK Content-Length: 1750 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/plugins/ajax-calendar/js/microajax.js | 200 OK Content-Length: 893 Content-Type: application/javascript | clean |
http://static.punjabitribuneonline.com/wp-content/themes/punjabinew/design/beta/js/script.js?ver=1334234717 | 200 OK Content-Length: 1669 Content-Type: application/javascript | clean |
http://is.gd/gzkj6O | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 16:55:23 GMT Location: http://chrispreece.com/u9104d3/ Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 CF-RAY: 17745863268805e1-WAW Set-Cookie: __cfduid=dd0e7e30792e8409fc4adcd435c5796441412960123381; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.is.gd; HttpOnly X-Powered-By: PHP/5.2.17 | clean |
http://chrispreece.com/u9104d3/ | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://chrispreece.com/test404page.js | 404 Not Found Content-Length: 236 Content-Type: text/html | clean |
http://cdn.widgetserver.com/syndication/subscriber/InsertWidget.js | 500 Can't connect to cdn.widgetserver.com:80 (Bad hostname) Content-Length: 172 Content-Type: text/plain | clean |
http://www.punjabitribuneonline.com//www.gmodules.com/ig/ifr?url=http://hosting.gmodules.com/ig/gadgets/file/112448834216921062787/daily-horoscope-1.xml&synd=open&w=300&h=325&border=%23ffffff%7C3px%2C1px+solid+%23999999&output=js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0, public Connection: close Date: Fri, 10 Oct 2014 16:54:34 GMT Pragma: no-cache Location: http://punjabitribuneonline.com/www.gmodules.com/ig/ifr?url=http://hosting.gmodules.com/ig/gadgets/file/112448834216921062787/daily-horoscope-1.xml&synd=open&w=300&h=325&border=%23ffffff%7C3px%2C1px+solid+%23999999&output=js/ Server: Apache/2.2.22 (Ubuntu) Vary: Cookie,Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 10 Oct 2014 16:54:35 GMT X-Pingback: http://punjabitribuneonline.com/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.9 | clean |
http://punjabitribuneonline.com/www.gmodules.com/ig/ifr?url=http://hosting.gmodules.com/ig/gadgets/file/112448834216921062787/daily-horoscope-1.xml&synd=open&w=300&h=325&border=%23ffffff%7c3px%2c1px+solid+%23999999&output=js/ | 404 Not Found Content-Length: 58095 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=punjabitribuneonline.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://punjabitribuneonline.com/
Result: punjabitribuneonline.com is not infected or malware details are not published yet.
Result: punjabitribuneonline.com is not infected or malware details are not published yet.