Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: reforn.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Wed, 10 Sep 2014 13:12:29 GMT
Pragma: no-cache
Server: nginx/1.6.1
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Wed, 10 Sep 2014 13:12:29 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 69f115555892ea779d6e6c8d1d8f3de8=06a6ad0a32b8048fcdfe1a05ae8d2764; path=/
Set-Cookie: virtuemart=06a6ad0a32b8048fcdfe1a05ae8d2764
GET / HTTP/1.1
Host: reforn.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Wed, 10 Sep 2014 13:12:29 GMT
Pragma: no-cache
Server: nginx/1.6.1
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Wed, 10 Sep 2014 13:12:29 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 69f115555892ea779d6e6c8d1d8f3de8=06a6ad0a32b8048fcdfe1a05ae8d2764; path=/
Set-Cookie: virtuemart=06a6ad0a32b8048fcdfe1a05ae8d2764
Second query (visit from search engine):
GET / HTTP/1.1
Host: reforn.com
Referer: http://www.google.com/search?q=reforn.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: reforn.com
Referer: http://www.google.com/search?q=reforn.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://reforn.com/ | 200 OK Content-Length: 71919 Content-Type: text/html | clean |
http://reforn.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://reforn.com/plugins/system/jcemediabox/js/jcemediabox.js?version=112 | 200 OK Content-Length: 53121 Content-Type: application/javascript | clean |
http://reforn.com/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 21474 Content-Type: application/javascript | clean |
http://reforn.com/plugins/system/rokbox/themes/dark/rokbox-config.js | 200 OK Content-Length: 2600 Content-Type: application/javascript | clean |
http://reforn.com/media/com_acymailing/js/acymailing_module.js | 200 OK Content-Length: 4882 Content-Type: application/javascript | clean |
http://reforn.com/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/themes/vmtheme001&file[0]=theme.js&subdir[1]=/js/extjs2&file[1]=yui-utilities.js&subdir[2]=/js/extjs2&file[2]=ext-yui-adapter.js&subdir[3]=/js/extjs2&file[3]=ext-all.js | 200 OK Content-Length: 300768 Content-Type: text/javascript | clean |
http://reforn.com/templates/vm_sample/scripts/eqal_column.js | 200 OK Content-Length: 325 Content-Type: application/javascript | clean |
http://reforn.com/index.php | 200 OK Content-Length: 71937 Content-Type: text/html | clean |
http://reforn.com/index.php?option=com_content&view=frontpage&Itemid=1 | 200 OK Content-Length: 72288 Content-Type: text/html | clean |
http://reforn.com/index.php?option=com_content&view=article&id=3&Itemid=2 | 200 OK Content-Length: 68629 Content-Type: text/html | clean |
http://reforn.com/index.php?option=com_virtuemart&Itemid=4 | 200 OK Content-Length: 76397 Content-Type: text/html | clean |
http://reforn.com/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/themes/vmtheme001&file[0]=theme.js&subdir[1]=/js&file[1]=sleight.js&subdir[2]=/js/mootools&file[2]=mootools-release-1.11.js&subdir[3]=/js/mootools&file[3]=mooPrompt.js | 200 OK Content-Length: 56350 Content-Type: text/javascript | clean |
http://reforn.com/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/themes/vmtheme001&file[0]=theme.js&subdir[1]=/js&file[1]=sleight.js&subdir[2]=/js/mootools&file[2]=mootools-release-1.11.js&subdir[3]=/js/mootools&file[3]=mooPrompt.js&subdir[4]=/js/extjs2&file[4]=yui-utilities.js&subdir[5]=/js/extjs2&file[5]=ext-yui-adapter.js&subdir[6]=/js/extjs2&file[6]=ext-all.js | 200 OK Content-Length: 300745 Content-Type: text/javascript | clean |
http://reforn.com/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/js&file[0]=wz_tooltip.js | 200 OK Content-Length: 36758 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=reforn.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://reforn.com/
Result: reforn.com is not infected or malware details are not published yet.
Result: reforn.com is not infected or malware details are not published yet.