Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ramazanumresi.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ramazanumresi.net/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ramazanumresi.net/ | 200 OK Content-Length: 37738 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.luksumreturlari.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="tr-tr" lang="tr-tr" > <head> <base href="http://ramazanumresi.net/" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="keywords" ...[4207 bytes skipped]... | ||
http://ramazanumresi.net/media/system/js/modal.js | 200 OK Content-Length: 10588 Content-Type: application/javascript | clean |
http://ramazanumresi.net/components/com_k2/js/k2.js | 200 OK Content-Length: 3077 Content-Type: application/javascript | clean |
http://ramazanumresi.net/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://ramazanumresi.net/modules/mod_jv_cu3er/assets/js/swfobject/swfobject.js | 200 OK Content-Length: 25560 Content-Type: application/javascript | clean |
http://ramazanumresi.net/modules/mod_lofk2slideshow/assets/script_jl15x.js | 200 OK Content-Length: 9598 Content-Type: application/javascript | clean |
http://ramazanumresi.net/templates/enucuzumre/jquery.js | 200 OK Content-Length: 72174 Content-Type: application/javascript | clean |
http://ramazanumresi.net/templates/enucuzumre/script.js | 200 OK Content-Length: 6452 Content-Type: application/javascript | clean |
http://ramazanumresi.net/templates/enucuzumre/swfobject.js | 200 OK Content-Length: 10235 Content-Type: application/javascript | clean |
http://connect.facebook.net/tr_TR/all.js | 200 OK Content-Length: 160942 Content-Type: application/x-javascript | clean |
http://widgets.fbshare.me/files/fbshare.js | 200 OK Content-Length: 1566 Content-Type: application/x-javascript | clean |
http://apis.google.com/js/plusone.js | 200 OK Content-Length: 12387 Content-Type: application/javascript | clean |
http://ramazanumresi.net/modules/mod_jscal2_for_joomla/src/js/jscal2.js | 200 OK Content-Length: 34371 Content-Type: application/javascript | clean |
http://ramazanumresi.net/modules/mod_jscal2_for_joomla/src/js/lang/tr.js | 200 OK Content-Length: 1366 Content-Type: application/javascript | clean |
http://ramazanumresi.net/modules/mod_wmtFlipClock/Scripts/swfobject_modified.js | 200 OK Content-Length: 21696 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ramazanumresi.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 15 Aug 2014 06:24:56 GMT
Server: LiteSpeed
Content-Type: text/html
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: ramazanumresi.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 15 Aug 2014 06:24:56 GMT
Server: LiteSpeed
Content-Type: text/html
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: ramazanumresi.net
Referer: http://www.google.com/search?q=ramazanumresi.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ramazanumresi.net
Referer: http://www.google.com/search?q=ramazanumresi.net
Result:
The result is similar to the first query. There are no suspicious redirects found.