Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://ranchofitness.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: ranchofitness.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sat, 20 Sep 2014 21:25:13 GMT Location: http://goo.gl/0rXySb Server: Apache/2.2.3 (CentOS) Content-Length: 286 Content-Type: text/html; charset=iso-8859-1 | malicious |
URL: http://goo.gl/0rXySb (imitation of visitor from search engine) GET /0rXySb HTTP/1.1 Host: goo.gl Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Sat, 20 Sep 2014 21:54:02 GMT Pragma: no-cache Age: 142 Location: http://sh.oowoo.ru/redsh.php Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Mon, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 80:quic,p=0.002 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | malicious |
URL: http://sh.oowoo.ru/redsh.php (imitation of visitor from search engine) GET /redsh.php HTTP/1.1 Host: sh.oowoo.ru Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Found Connection: close Date: Sat, 20 Sep 2014 21:54:54 GMT Location: http://fastmambo.biz/?s=370 Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=CP1251 X-Powered-By: PHP/5.2.17 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://ranchofitness.com/ | 200 OK Content-Length: 15199 Content-Type: text/html | clean |
http://ranchofitness.com/wp-includes/js/comment-reply.js?ver=20090102 | 200 OK Content-Length: 786 Content-Type: application/x-javascript | clean |
http://ranchofitness.com/?page_id=10 | 200 OK Content-Length: 15181 Content-Type: text/html | clean |
http://ranchofitness.com/?page_id=6 | 200 OK Content-Length: 15242 Content-Type: text/html | clean |
http://ranchofitness.com/?page_id=8 | 200 OK Content-Length: 15256 Content-Type: text/html | clean |
http://ranchofitness.com/wp-login.php | 200 OK Content-Length: 2124 Content-Type: text/html | clean |
http://ranchofitness.com/wp-login.php?action=lostpassword | 200 OK Content-Length: 1733 Content-Type: text/html | clean |
http://ranchofitness.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sat, 20 Sep 2014 21:25:25 GMT Location: http://goo.gl/0rXySb Server: Apache/2.2.3 (CentOS) Content-Length: 286 Content-Type: text/html; charset=iso-8859-1 | clean |
http://goo.gl/0rxysb | 404 Not Found Content-Length: 4438 Content-Type: text/html | clean |
http://goo.gl/static/0050.urlshortener.js | 200 OK Content-Length: 66150 Content-Type: text/javascript | clean |
http://ranchofitness.com//www.google.com/support/websearch/bin/answer.py?answer=190768/ | HTTP/1.1 302 Found Connection: close Date: Sat, 20 Sep 2014 21:25:26 GMT Location: http://goo.gl/0rXySb Server: Apache/2.2.3 (CentOS) Content-Length: 286 Content-Type: text/html; charset=iso-8859-1 | clean |
http://goo.gl/test404page.js | 404 Not Found Content-Length: 4446 Content-Type: text/html | clean |
http://goo.gl/ | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Sat, 20 Sep 2014 21:56:37 GMT Location: https://www.google.com/accounts/ServiceLogin?service=urlshortener&continue=http://goo.gl/?authed%3D1&followup=http://goo.gl/?authed%3D1&passive=true&go=true Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Sep 2014 21:56:37 GMT Alternate-Protocol: 80:quic,p=0.002 Set-Cookie: authed=1;Path=/ X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/servicelogin?service=urlshortener&continue=http://goo.gl/?authed%3d1&followup=http://goo.gl/?authed%3d1&passive=true&go=true | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Sat, 20 Sep 2014 21:56:37 GMT Location: https://accounts.google.com/servicelogin?service=urlshortener&continue=http%3A%2F%2Fgoo.gl%2F%3Fauthed%3D1&followup=http%3A%2F%2Fgoo.gl%2F%3Fauthed%3D1&passive=true&go=true Server: GSE Content-Length: 370 Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Sep 2014 21:56:37 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/servicelogin?service=urlshortener&continue=http%3a%2f%2fgoo.gl%2f%3fauthed%3d1&followup=http%3a%2f%2fgoo.gl%2f%3fauthed%3d1&passive=true&go=true | HTTP/1.1 200 OK Cache-Control: private, max-age=0 Connection: close Date: Sat, 20 Sep 2014 21:56:37 GMT Server: GSE Content-Length: 1491 Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Sep 2014 21:56:37 GMT Alternate-Protocol: 443:quic,p=0.002 Set-Cookie: GAPS=1:n3VZ4CSRZy8HV3I3yTxIiapXZwVuhQ:9nlfwvv4ec1IpLj7;Path=/;Expires=Mon, 19-Sep-2016 21:56:37 GMT;Secure;HttpOnly;Priority=HIGH Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/& | 404 Not Found Content-Length: 1413 Content-Type: text/html | clean |
https://accounts.google.com//www.google.com/ | 404 Not Found Content-Length: 1413 Content-Type: text/html | clean |
http://accounts.google.com/test404page.js | 404 Not Found Content-Length: 1413 Content-Type: text/html | clean |
http://accounts.google.com//www.google.com/ | 404 Not Found Content-Length: 1413 Content-Type: text/html | clean |
http://goo.gl//www.google.com/support/websearch/bin/answer.py?answer=190768/ | 404 Not Found Content-Length: 4493 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ranchofitness.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ranchofitness.com/
Result: ranchofitness.com is not infected or malware details are not published yet.
Result: ranchofitness.com is not infected or malware details are not published yet.