Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ranzero.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ranzero.net
Result:
HTTP/1.1 302 Found
Cache-Control: private
Connection: close
Date: Fri, 05 Sep 2014 00:29:54 GMT
Location: http://dprtb.com/click?data=WEdLemwxa01vVnA5UTlGM3lBcC1xUFM5NHREX0paLWVURkgyLXd2a1NwT1N3cUw0WUZ6VGhLeXgzcDhZRGViUUxOeDNJT3d3Y2tNcmRVaWxxLWluWTFQOHpBRlNwaE1lWEZkeEx4WjhydmVNOHR0MjVZd2xiWjF3ckp0Z0VlYWdkcHZfQlRHUi0xQnpkRVhHcUNwTDR3Mg2&id=a131ffda-93ab-480c-a80e-9b27d87935c5
Server: Microsoft-IIS/7.5
Content-Length: 392
Content-Type: text/html; charset=utf-8
Access-Control-Allow-Origin: *
P3P: CP="NOI DSP COR CURa ADMa DEVa OUR IND OTC"
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 5.2
X-Powered-By: ASP.NET
X-ServerName: NLB6
...392 bytes of data.
GET / HTTP/1.1
Host: ranzero.net
Result:
HTTP/1.1 302 Found
Cache-Control: private
Connection: close
Date: Fri, 05 Sep 2014 00:29:54 GMT
Location: http://dprtb.com/click?data=WEdLemwxa01vVnA5UTlGM3lBcC1xUFM5NHREX0paLWVURkgyLXd2a1NwT1N3cUw0WUZ6VGhLeXgzcDhZRGViUUxOeDNJT3d3Y2tNcmRVaWxxLWluWTFQOHpBRlNwaE1lWEZkeEx4WjhydmVNOHR0MjVZd2xiWjF3ckp0Z0VlYWdkcHZfQlRHUi0xQnpkRVhHcUNwTDR3Mg2&id=a131ffda-93ab-480c-a80e-9b27d87935c5
Server: Microsoft-IIS/7.5
Content-Length: 392
Content-Type: text/html; charset=utf-8
Access-Control-Allow-Origin: *
P3P: CP="NOI DSP COR CURa ADMa DEVa OUR IND OTC"
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 5.2
X-Powered-By: ASP.NET
X-ServerName: NLB6
...392 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ranzero.net
Referer: http://www.google.com/search?q=ranzero.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ranzero.net
Referer: http://www.google.com/search?q=ranzero.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ranzero.net/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Fri, 05 Sep 2014 00:29:54 GMT Location: http://dprtb.com/click?data=WEdLemwxa01vVnA5UTlGM3lBcC1xUFM5NHREX0paLWVURkgyLXd2a1NwT1N3cUw0WUZ6VGhLeXgzcDhZRGViUUxOeDNJT3d3Y2tNcmRVaWxxLWluWTFQOHpBRlNwaE1lWEZkeEx4WjhydmVNOHR0MjVZd2xiWjF3ckp0Z0VlYWdkcHZfQlRHUi0xQnpkRVhHcUNwTDR3Mg2&id=a131ffda-93ab-480c-a80e-9b27d87935c5 Server: Microsoft-IIS/7.5 Content-Length: 392 Content-Type: text/html; charset=utf-8 Access-Control-Allow-Origin: * P3P: CP="NOI DSP COR CURa ADMa DEVa OUR IND OTC" X-AspNet-Version: 4.0.30319 X-AspNetMvc-Version: 5.2 X-Powered-By: ASP.NET X-ServerName: NLB6 | clean |
http://dprtb.com/click?data=wedlemwxa01vvna5utlgm3lbcc1xufm5nhrex0palwvurkgylxd2a1nwt1n3cuw0wuz6vghlexgzcdhzrgviuuxoednjt3d3y2tncmrvawxxlwluwtfqohpbrlnwae1lwezkeex4wjhydmvnohr0mjvzd2xiwjf3ckp0z0vlywdkchzfqlrhui0xqnpkrvhhcunwtdr3mg2&id=a131ffda-93ab-480c-a80e-9b27d87935c5 | 200 OK Content-Length: 46 Content-Type: text/html | clean |
http://dprtb.com/test404page.js | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |