Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=site.overstockbridalprom.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://site.overstockbridalprom.com/ | 200 OK Content-Length: 10145 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: bigtronic.pl <script type="text/javascript" src="http://delaracabamentos.com.br/mltools.js"></script><script type="text/javascript" src="http://tvenkiniai.eu/jstools.js"></script><script type="text/javascript" src="http://bigtronic.pl/jstools.js"></script><script type="text/javascript" src="http://rooftileconstruction.com/mltools.js"></script><script type="text/javascript" src="http://noclegi-zwierzyniec.pl/mltools.js"></script><script type="text/javascript" src="http://www.univisionnet.com/mltools.js></script><script type="text/javascript" src="http://rooftileconstruction.com/mltools.js"></script><script type= ...[11643 bytes skipped]... | ||
http://delaracabamentos.com.br/mltools.js | 404 Not Found Content-Length: 1050 Content-Type: text/html | clean |
http://delaracabamentos.com.br/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 07 Jun 2014 00:26:26 GMT Location: http://www.delaracabamentos.com.br/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: PHPSESSID=82gkr6h43shpa792mohjfiprp1; path=/; HttpOnly Set-Cookie: wfvt_909553476=53925c32ba534; expires=Sat, 07-Jun-2014 00:56:26 GMT; path=/ X-Pingback: http://www.delaracabamentos.com.br/xmlrpc.php | clean |
http://www.delaracabamentos.com.br/ | 200 OK Content-Length: 14689 Content-Type: text/html | clean |
http://www.delaracabamentos.com.br/wp-includes/js/jquery/jquery.js?ver=1.8.3 | 200 OK Content-Length: 93658 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/plugins/jquery-colorbox/js/jquery.colorbox-min.js?ver=1.3.21 | 200 OK Content-Length: 9710 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/plugins/jquery-colorbox/js/jquery-colorbox-wrapper-min.js?ver=4.6 | 200 OK Content-Length: 8067 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.3 | 200 OK Content-Length: 9986 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995 | 200 OK Content-Length: 26590 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.06 | 200 OK Content-Length: 1791 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/themes/delar/jscompressed/ajax.js | 200 OK Content-Length: 4041 Content-Type: application/x-javascript | clean |
http://www.delaracabamentos.com.br/wp-content/themes/delar/jscompressed/AC_RunActiveContent.js | 200 OK Content-Length: 8029 Content-Type: application/x-javascript | clean |
http://delaracabamentos.com.br/test404page.js | 404 Not Found Content-Length: 1050 Content-Type: text/html | clean |
http://tvenkiniai.eu/jstools.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 07 Jun 2014 00:26:37 GMT Pragma: no-cache Location: http://www.tvenkiniai.eu/jstools.js Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.tvenkiniai.eu/xmlrpc.php | clean |
http://www.tvenkiniai.eu/jstools.js | 404 Not Found Content-Length: 12359 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js | 200 OK Content-Length: 93868 Content-Type: text/javascript | clean |
http://www.tvenkiniai.eu/wp-content/themes/robiui/ad-gallery/jquery.ad-gallery.js | 200 OK Content-Length: 34628 Content-Type: text/js | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: site.overstockbridalprom.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sat, 07 Jun 2014 00:26:23 GMT
Age: 2
Server: YTS/1.20.28
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Last-Modified: Fri, 06 Jun 2014 22:45:54 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: BX=1lbvb6d9p4n1f&b=3&s=du; expires=Tue, 07-Jun-2016 00:26:24 GMT; path=/; domain=.overstockbridalprom.com
GET / HTTP/1.1
Host: site.overstockbridalprom.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sat, 07 Jun 2014 00:26:23 GMT
Age: 2
Server: YTS/1.20.28
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Last-Modified: Fri, 06 Jun 2014 22:45:54 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: BX=1lbvb6d9p4n1f&b=3&s=du; expires=Tue, 07-Jun-2016 00:26:24 GMT; path=/; domain=.overstockbridalprom.com
Second query (visit from search engine):
GET / HTTP/1.1
Host: site.overstockbridalprom.com
Referer: http://www.google.com/search?q=site.overstockbridalprom.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: site.overstockbridalprom.com
Referer: http://www.google.com/search?q=site.overstockbridalprom.com
Result:
The result is similar to the first query. There are no suspicious redirects found.