Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=rimaldicreazione.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: othoniel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 02 Jul 2014 16:15:13 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6469
Content-Type: text/html
Last-Modified: Wed, 15 Jan 2014 07:13:24 GMT
...6469 bytes of data.
GET / HTTP/1.1
Host: othoniel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 02 Jul 2014 16:15:13 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6469
Content-Type: text/html
Last-Modified: Wed, 15 Jan 2014 07:13:24 GMT
...6469 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: othoniel.com
Referer: http://www.google.com/search?q=othoniel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: othoniel.com
Referer: http://www.google.com/search?q=othoniel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://rimaldicreazione.com/ | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:17 GMT Location: http://www.sandalo.com Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/ | 200 OK Content-Length: 34279 Content-Type: text/html | clean |
http://www.sandalo.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js | 200 OK Content-Length: 72174 Content-Type: text/javascript | clean |
http://rimaldicreazione.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.noconflict.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:20 GMT Location: http://www.sandalo.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.noconflict.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.noconflict.js | 200 OK Content-Length: 81 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.nivo.slider.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:20 GMT Location: http://www.sandalo.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.nivo.slider.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/modules/mod_ariimageslider/mod_ariimageslider/js/jquery.nivo.slider.js | 200 OK Content-Length: 6503 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/media/com_acymailing/js/acymailing_module.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:20 GMT Location: http://www.sandalo.com/media/com_acymailing/js/acymailing_module.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/media/com_acymailing/js/acymailing_module.js | 200 OK Content-Length: 5028 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/media/system/js/modal.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:21 GMT Location: http://www.sandalo.com/media/system/js/modal.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/media/system/js/modal.js | 200 OK Content-Length: 10588 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/templates/joomspirit_31/lib/js/jquery-1.6.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:21 GMT Location: http://www.sandalo.com/templates/joomspirit_31/lib/js/jquery-1.6.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/templates/joomspirit_31/lib/js/jquery-1.6.js | 200 OK Content-Length: 232651 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/templates/joomspirit_31/lib/js/moomenuv.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:22 GMT Location: http://www.sandalo.com/templates/joomspirit_31/lib/js/moomenuv.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/templates/joomspirit_31/lib/js/moomenuv.js | 200 OK Content-Length: 4752 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/templates/joomspirit_31/lib/js/accordionmenu.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:23 GMT Location: http://www.sandalo.com/templates/joomspirit_31/lib/js/accordionmenu.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/templates/joomspirit_31/lib/js/accordionmenu.js | 200 OK Content-Length: 3665 Content-Type: application/javascript | clean |
http://rimaldicreazione.com/templates/joomspirit_31/lib/js/jquery.tooltip.min.js | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:23 GMT Location: http://www.sandalo.com/templates/joomspirit_31/lib/js/jquery.tooltip.min.js Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/templates/joomspirit_31/lib/js/jquery.tooltip.min.js | 200 OK Content-Length: 5499 Content-Type: application/javascript | clean |
http://www.sandalo.com/modules/mod_virtuemart_flexible_dropdown_cart/flexible_dropdown/flexible_dropdown.js | 200 OK Content-Length: 5627 Content-Type: application/javascript | clean |
http://connect.facebook.net/en_US/all.js | 200 OK Content-Length: 167017 Content-Type: application/x-javascript | clean |
http://rimaldicreazione.com/index.php?page=shop.cart_reset&option=com_virtuemart&option2=com_content&product_id=&category_id=&return=&flypage=&Itemid=1 | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:24 GMT Location: http://www.sandalo.com/index.php?page=shop.cart_reset&option=com_virtuemart&option2=com_content&product_id=&category_id=&return=&flypage=&Itemid=1 Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/index.php?page=shop.cart_reset&option=com_virtuemart&option2=com_content&product_id=&category_id=&return=&flypage=&itemid=1 | HTTP/1.1 303 See other Connection: close Date: Tue, 01 Jul 2014 07:18:24 GMT Location: http://www.sandalo.com/index.php?page=shop.cart_reset&option=com_virtuemart&option2=com_content&product_id=&category_id=&return=&flypage=&itemid=1&vmcchk=1&Itemid=56 Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8g PHP/5.2.11 with Suhosin-Patch Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: d4e878dffca71218a9f91ad6b64c7d55=rbltr1qb51uft9d7u7qehmbcu6; path=/ Set-Cookie: lang=deleted; expires=Mon, 01-Jul-2013 07:18:23 GMT; path=/ Set-Cookie: jfcookie=deleted; expires=Mon, 01-Jul-2013 07:18:23 GMT; path=/ Set-Cookie: jfcookie[lang]=deleted; expires=Mon, 01-Jul-2013 07:18:23 GMT; path=/ Set-Cookie: virtuemart=rbltr1qb51uft9d7u7qehmbcu6 | clean |
http://www.sandalo.com/index.php?page=shop.cart_reset&option=com_virtuemart&option2=com_content&product_id=&category_id=&return=&flypage=&itemid=1&vmcchk=1&itemid=56 | HTTP/1.1 303 See other Connection: close Date: Tue, 01 Jul 2014 07:18:25 GMT Location: http://www.sandalo.com/ Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8g PHP/5.2.11 with Suhosin-Patch Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: d4e878dffca71218a9f91ad6b64c7d55=odvmgif08bohipilifk32t09p4; path=/ Set-Cookie: lang=deleted; expires=Mon, 01-Jul-2013 07:18:24 GMT; path=/ Set-Cookie: jfcookie=deleted; expires=Mon, 01-Jul-2013 07:18:24 GMT; path=/ Set-Cookie: jfcookie[lang]=deleted; expires=Mon, 01-Jul-2013 07:18:24 GMT; path=/ Set-Cookie: virtuemart=odvmgif08bohipilifk32t09p4 | clean |
http://www.sandalo.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://rimaldicreazione.com/es/xmap | HTTP/1.1 302 Found Connection: close Date: Tue, 01 Jul 2014 07:18:25 GMT Location: http://www.sandalo.com/es/xmap Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.2-1ubuntu4.22 | malicious |
http://www.sandalo.com/es/xmap | 200 OK Content-Length: 132593 Content-Type: text/html | clean |