Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: socalrunning.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 17 Jun 2014 16:10:14 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_3911400200=53a0686864cf5; expires=Tue, 17-Jun-2014 16:40:16 GMT; path=/
X-Pingback: http://socalrunning.com/xmlrpc.php
GET / HTTP/1.1
Host: socalrunning.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 17 Jun 2014 16:10:14 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_3911400200=53a0686864cf5; expires=Tue, 17-Jun-2014 16:40:16 GMT; path=/
X-Pingback: http://socalrunning.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: socalrunning.com
Referer: http://www.google.com/search?q=socalrunning.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: socalrunning.com
Referer: http://www.google.com/search?q=socalrunning.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.socalrunning.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 17 Jun 2014 16:10:12 GMT Location: http://socalrunning.com/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: wfvt_3911400200=53a06865e5f36; expires=Tue, 17-Jun-2014 16:40:13 GMT; path=/ X-Pingback: http://socalrunning.com/xmlrpc.php | clean |
http://socalrunning.com/ | 200 OK Content-Length: 77560 Content-Type: text/html | clean |
http://socalrunning.com/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: text/javascript | clean |
http://socalrunning.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://socalrunning.com/wp-content/plugins/google-analyticator/external-tracking.min.js?ver=6.4.7.3 | 200 OK Content-Length: 1190 Content-Type: text/javascript | clean |
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
http://www.socalrunning.com/chirunning-workshops/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 17 Jun 2014 16:10:20 GMT Location: http://socalrunning.com/chirunning-workshops/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: wfvt_3911400200=53a0686f69603; expires=Tue, 17-Jun-2014 16:40:23 GMT; path=/ X-Pingback: http://socalrunning.com/xmlrpc.php | clean |
http://socalrunning.com/chirunning-workshops/ | 200 OK Content-Length: 57292 Content-Type: text/html | clean |
http://socalrunning.com/featured-races/ | 200 OK Content-Length: 41851 Content-Type: text/html | clean |
http://socalrunning.com/testimonials/ | 200 OK Content-Length: 79278 Content-Type: text/html | clean |
http://socalrunning.com/honolulu-marathon-with-the-sole-runners-december-8-12-2011/ | 200 OK Content-Length: 43218 Content-Type: text/html | clean |
http://socalrunning.com/palos-dena-ultra-challenge-52-4-26-2/ | 200 OK Content-Length: 42183 Content-Type: text/html | clean |
http://socalrunning.com/gary-smith/ | 200 OK Content-Length: 41893 Content-Type: text/html | clean |
http://socalrunning.com/free-chirunning-clinic-at-the-dog-haus-in-old-town-pasadena-tuesday-june-17-6-pm/ | 200 OK Content-Length: 44596 Content-Type: text/html | clean |
http://www.google.com/recaptcha/api/challenge?k=6Leb2uMSAAAAAJ-gfNlxTtzcO9w0T2A0G2tlrcwp | 200 OK Content-Length: 8939 Content-Type: text/javascript | clean |
http://socalrunning.com/wp-content/uploads/2014/06/Screen-Shot-2014-06-16-at-8.59.47-AM.png | 200 OK Content-Length: 303729 Content-Type: image/png | clean |
http://socalrunning.com/test404page.js | 404 Not Found Content-Length: 37991 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=socalrunning.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://socalrunning.com/
Result: socalrunning.com is not infected or malware details are not published yet.
Result: socalrunning.com is not infected or malware details are not published yet.