Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sardies.org
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sat, 09 May 2015 02:47:13 GMT
Location: http://www.sardegnadies.it
Server: Apache/2
Content-Length: 210
Content-Type: text/html; charset=iso-8859-1
...210 bytes of data.
GET / HTTP/1.1
Host: sardies.org
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sat, 09 May 2015 02:47:13 GMT
Location: http://www.sardegnadies.it
Server: Apache/2
Content-Length: 210
Content-Type: text/html; charset=iso-8859-1
...210 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sardies.org
Referer: http://www.google.com/search?q=sardies.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sardies.org
Referer: http://www.google.com/search?q=sardies.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://sardies.org/ | HTTP/1.1 302 Found Connection: close Date: Sat, 09 May 2015 02:47:13 GMT Location: http://www.sardegnadies.it Server: Apache/2 Content-Length: 210 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.sardegnadies.it/ | 200 OK Content-Length: 144388 Content-Type: text/html | clean |
http://www.sardegnadies.it/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/superfish.js?ver=3.8.8 | 200 OK Content-Length: 3823 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/jquery.easing_1.3.js?ver=3.8.8 | 200 OK Content-Length: 8097 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/lofslider.js?ver=3.8.8 | 200 OK Content-Length: 14104 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/jcarousellite_1.0.1.min.js?ver=3.8.8 | 200 OK Content-Length: 2383 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/jquery.masonry.min.js?ver=3.8.8 | 200 OK Content-Length: 5467 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/jquery.mobilemenu.js?ver=3.8.8 | 200 OK Content-Length: 1827 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/themes/max-magazine/js/custom.js?ver=3.8.8 | 200 OK Content-Length: 1384 Content-Type: application/javascript | clean |
http://www.sardegnadies.it/wp-content/plugins/news-ticker/cycle.js?ver=3.8.8 | 200 OK Content-Length: 53738 Content-Type: application/javascript | clean |
http://sardies.org//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ | HTTP/1.1 302 Found Connection: close Date: Sat, 09 May 2015 02:47:17 GMT Location: http://www.sardegnadies.itpagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ Server: Apache/2 Content-Length: 265 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.sardegnadies.itpagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ | 500 Can't connect to www.sardegnadies.itpagead2.googlesyndication.com:80 Content-Length: 223 Content-Type: text/plain | clean |
http://www.sardegnadies.itpagead2.googlesyndication.com/test404page.js | 500 Can't connect to www.sardegnadies.itpagead2.googlesyndication.com:80 Content-Length: 223 Content-Type: text/plain | clean |
http://www.ilmeteo.net/wid_loader/e014cbdc894abd90c4fad1cbc702a87a | 200 OK Content-Length: 1369 Content-Type: application/javascript | clean |
https://apis.google.com/js/platform.js | 200 OK Content-Length: 37301 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sardies.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sardies.org/
Result: sardies.org is not infected or malware details are not published yet.
Result: sardies.org is not infected or malware details are not published yet.