Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tarutao.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 04 Sep 2014 05:40:20 GMT
Location: http://www.tarutao.com/
Server: Apache
Content-Length: 0
Content-Type: text/html
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=6mvhcsrav167tvb5c88rvopfm0; path=/
...0 bytes of data.
GET / HTTP/1.1
Host: tarutao.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 04 Sep 2014 05:40:20 GMT
Location: http://www.tarutao.com/
Server: Apache
Content-Length: 0
Content-Type: text/html
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=6mvhcsrav167tvb5c88rvopfm0; path=/
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tarutao.com
Referer: http://www.google.com/search?q=tarutao.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tarutao.com
Referer: http://www.google.com/search?q=tarutao.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://tarutao.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 04 Sep 2014 05:40:20 GMT Location: http://www.tarutao.com/ Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=6mvhcsrav167tvb5c88rvopfm0; path=/ | clean |
http://www.tarutao.com/ | 200 OK Content-Length: 49394 Content-Type: text/html | clean |
http://www.tarutao.com/media/system/js/modal.js | 200 OK Content-Length: 10552 Content-Type: text/javascript | clean |
http://www.tarutao.com/components/com_k2/js/k2.js | 200 OK Content-Length: 3077 Content-Type: text/javascript | clean |
http://tarutao.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: text/javascript | clean |
http://tarutao.com/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 22076 Content-Type: text/javascript | clean |
http://tarutao.com/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: text/javascript | clean |
http://tarutao.com/components/com_gantry/js/gantry-buildspans.js | 200 OK Content-Length: 720 Content-Type: text/javascript | clean |
http://tarutao.com/components/com_gantry/js/gantry-inputs.js | 200 OK Content-Length: 2876 Content-Type: text/javascript | clean |
http://tarutao.com/components/com_gantry/js/gantry-smartload.js | 200 OK Content-Length: 2041 Content-Type: text/javascript | clean |
http://tarutao.com/start/tarutao/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 04 Sep 2014 05:40:24 GMT Location: http://www.tarutao.com/start/tarutao/ Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=2iorged11k6bbmco7ecp5s9960; path=/ | clean |
http://www.tarutao.com/start/tarutao/ | 200 OK Content-Length: 29548 Content-Type: text/html | clean |
http://www.tarutao.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: text/javascript | clean |
http://tarutao.com/start/results/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 04 Sep 2014 05:40:26 GMT Location: http://www.tarutao.com/start/results/ Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=684ut1lg8017ec4dbabfsibbr5; path=/ | clean |
http://www.tarutao.com/start/results/ | 200 OK Content-Length: 34101 Content-Type: text/html | clean |
http://www.tarutao.com/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 22076 Content-Type: text/javascript | clean |
http://tarutao.com/start/author/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 04 Sep 2014 05:40:27 GMT Location: http://www.tarutao.com/start/author/ Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 6e4339f27eb42e1c2091e5b0ee78c9c1=45koq8g9bv2mb5a35m8ud75cg3; path=/ | clean |
http://www.tarutao.com/start/author/ | 200 OK Content-Length: 29970 Content-Type: text/html | clean |
http://www.tarutao.com/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tarutao.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tarutao.com/
Result: tarutao.com is not infected or malware details are not published yet.
Result: tarutao.com is not infected or malware details are not published yet.