Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=questionsanswerssite.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://questionsanswerssite.net/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: questionsanswerssite.net
Result:
HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 16 Dec 2014 06:36:46 GMT
Pragma: no-cache
Location: /RU
Server: nginx
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT", CP="CAO PSA OUR"
Set-Cookie: PHPSESSID=4mert7mih82pi09fube1117eo2; path=/
...0 bytes of data.
GET / HTTP/1.1
Host: questionsanswerssite.net
Result:
HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 16 Dec 2014 06:36:46 GMT
Pragma: no-cache
Location: /RU
Server: nginx
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT", CP="CAO PSA OUR"
Set-Cookie: PHPSESSID=4mert7mih82pi09fube1117eo2; path=/
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: questionsanswerssite.net
Referer: http://www.google.com/search?q=questionsanswerssite.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: questionsanswerssite.net
Referer: http://www.google.com/search?q=questionsanswerssite.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://questionsanswerssite.net/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 16 Dec 2014 06:36:46 GMT Pragma: no-cache Location: /RU Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT", CP="CAO PSA OUR" Set-Cookie: PHPSESSID=4mert7mih82pi09fube1117eo2; path=/ | clean |
http://questionsanswerssite.net/ru | 200 OK Content-Length: 3521 Content-Type: text/html | clean |
http://questionsanswerssite.net/ru/support/service | 200 OK Content-Length: 4420 Content-Type: text/html | clean |
http://st.questionsanswerssite.net/tpl/js/jquery.min.js | 200 OK Content-Length: 57254 Content-Type: application/x-javascript | clean |
http://questionsanswerssite.net/js/legals.js | 200 OK Content-Length: 814 Content-Type: application/x-javascript | clean |
http://questionsanswerssite.net/ru/support/faq | 200 OK Content-Length: 13626 Content-Type: text/html | clean |
http://www.google.com/recaptcha/api/challenge?k=6Lebd8oSAAAAALDj1XWh5wi1jGQvZQWm_dw6qqNA | 200 OK Content-Length: 8651 Content-Type: text/javascript | clean |
http://questionsanswerssite.net/ru/support/contact | 200 OK Content-Length: 7827 Content-Type: text/html | clean |
http://questionsanswerssite.net/js/contact.form.js | 200 OK Content-Length: 4473 Content-Type: application/x-javascript | clean |
http://questionsanswerssite.net/test404page.js | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |