Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tec-ma.be
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 10 May 2014 02:39:27 GMT
Location: http://www.tec-ma.be/
Server: Apache
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_1472633993=536d9160cdb4a; expires=Sat, 10-May-2014 03:09:28 GMT; path=/; httponly
X-Pingback: http://www.tec-ma.be/xmlrpc.php
X-Powered-By: PHP/5.3.28
GET / HTTP/1.1
Host: tec-ma.be
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 10 May 2014 02:39:27 GMT
Location: http://www.tec-ma.be/
Server: Apache
Content-Type: text/html; charset=UTF-8
Set-Cookie: wfvt_1472633993=536d9160cdb4a; expires=Sat, 10-May-2014 03:09:28 GMT; path=/; httponly
X-Pingback: http://www.tec-ma.be/xmlrpc.php
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: tec-ma.be
Referer: http://www.google.com/search?q=tec-ma.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tec-ma.be
Referer: http://www.google.com/search?q=tec-ma.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://tec-ma.be/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 10 May 2014 02:39:27 GMT Location: http://www.tec-ma.be/ Server: Apache Content-Type: text/html; charset=UTF-8 Set-Cookie: wfvt_1472633993=536d9160cdb4a; expires=Sat, 10-May-2014 03:09:28 GMT; path=/; httponly X-Pingback: http://www.tec-ma.be/xmlrpc.php X-Powered-By: PHP/5.3.28 | clean |
http://www.tec-ma.be/ | 200 OK Content-Length: 46780 Content-Type: text/html | clean |
http://www.tec-ma.be/wp-content/themes/tec-ma/js/jquery.js | 200 OK Content-Length: 57254 Content-Type: application/javascript | clean |
http://www.tec-ma.be/wp-content/plugins/wordpress-form-manager/js/userscripts.js?ver=3.8.3 | 200 OK Content-Length: 7442 Content-Type: application/javascript | clean |
http://tec-ma.be/skype:patrick.colot?chat | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 10 May 2014 02:39:33 GMT Pragma: no-cache Location: http://www.tec-ma.be/skype:patrick.colot?chat Server: Apache Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: wfvt_1472633993=536d91660ae4b; expires=Sat, 10-May-2014 03:09:34 GMT; path=/; httponly X-Pingback: http://www.tec-ma.be/xmlrpc.php X-Powered-By: PHP/5.3.28 | clean |
http://www.tec-ma.be/skype:patrick.colot?chat | 404 Not Found Content-Length: 16969 Content-Type: text/html | clean |
http://www.tec-ma.be/les-enonces-tec-ma/ | 200 OK Content-Length: 22575 Content-Type: text/html | clean |
http://www.tec-ma.be/activites/interim-management-2/ | 200 OK Content-Length: 23431 Content-Type: text/html | clean |
http://www.tec-ma.be/la-voie-du-loner/ | 200 OK Content-Length: 28279 Content-Type: text/html | clean |
http://www.tec-ma.be/mars-venus-aussi-dans-lentrepreprise-conference-a-linitiative-de-bnp-paribas-fortis-zone-hainaut-brabant-wallon/ | 200 OK Content-Length: 75327 Content-Type: text/html | clean |
http://www.tec-ma.be/login/ | 200 OK Content-Length: 18137 Content-Type: text/html | clean |
http://www.tec-ma.be/contactez-tec-ma/ | 200 OK Content-Length: 23655 Content-Type: text/html | clean |
http://www.tec-ma.be/contactez-tec-ma/skype:patrick.colot?chat | 404 Not Found Content-Length: 16986 Content-Type: text/html | clean |
http://www.tec-ma.be/test404page.js | 404 Not Found Content-Length: 16959 Content-Type: text/html | clean |
http://www.tec-ma.be/login/skype:patrick.colot?chat | 404 Not Found Content-Length: 16975 Content-Type: text/html | clean |
http://www.tec-ma.be/article-sur-la-motivation-des-collaborateurs/ | 200 OK Content-Length: 20780 Content-Type: text/html | clean |
http://www.tec-ma.be/amis-partenaires-collaborations-reseaux-amis/ | 200 OK Content-Length: 51742 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tec-ma.be
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tec-ma.be/
Result: tec-ma.be is not infected or malware details are not published yet.
Result: tec-ma.be is not infected or malware details are not published yet.