Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thecandidaconnection.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: riportal.mobi
Result:
HTTP/1.1 400 Bad Request
Connection: close
Date: Thu, 24 Jul 2014 13:56:13 GMT
Content-Length: 39
Content-Type: text/html
...39 bytes of data.
GET / HTTP/1.1
Host: riportal.mobi
Result:
HTTP/1.1 400 Bad Request
Connection: close
Date: Thu, 24 Jul 2014 13:56:13 GMT
Content-Length: 39
Content-Type: text/html
...39 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: riportal.mobi
Referer: http://www.google.com/search?q=riportal.mobi
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: riportal.mobi
Referer: http://www.google.com/search?q=riportal.mobi
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://thecandidaconnection.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Fri, 26 Dec 2014 12:48:23 GMT Age: 1 Location: http://karenhubert.com Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://karenhubert.com/ | 200 OK Content-Length: 64714 Content-Type: text/html | malicious |
Page code contains blacklisted domain: phoenix-credit.com <!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"> <head> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <title>Karen Hubert </title> <script type="text/javascript" src="https://maps.google.com/maps/api/js?v=3.exp&sensor=false&language=en"></script ...[4089 bytes skipped]... Hidden iFrame found. size: 0x0 src: http://google.com <iframe src="http://google.com" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no> Malicious iFrame found. size: 0x0 src: http://phoenix-credit.com/wp-content/cache.php This URL is marked by Google as suspicious <iframe src="http://phoenix-credit.com/wp-content/cache.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no> | ||
https://maps.google.com/maps/api/js?v=3.exp&sensor=false&language=en | 200 OK Content-Length: 4222 Content-Type: text/javascript | clean |
http://karenhubert.com/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/LayerSlider/js/layerslider.kreaturamedia.jquery.js?ver=4.5.5 | 200 OK Content-Length: 47712 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/LayerSlider/js/jquery-easing-1.3.js?ver=1.3.0 | 200 OK Content-Length: 8152 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/LayerSlider/js/jquerytransit.js?ver=0.9.9 | 200 OK Content-Length: 6565 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/LayerSlider/js/layerslider.transitions.js?ver=4.5.5 | 200 OK Content-Length: 21148 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/revslider/rs-plugin/js/jquery.themepunch.plugins.min.js?ver=4.1 | 200 OK Content-Length: 17331 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?ver=4.1 | 200 OK Content-Length: 56235 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/tf-flexslider/assets/js/jquery.mousewheel.min.js?ver=2.1.0-20121206 | 200 OK Content-Length: 1007 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/framework/plugins/tf-flexslider/assets/js/jquery.flexslider.min.js?ver=2.1.0-20121206 | 200 OK Content-Length: 16688 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/js/modernizr.js?ver=4.1 | 200 OK Content-Length: 10924 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/js/jquery.carouFredSel-6.2.1-packed.js?ver=4.1 | 200 OK Content-Length: 54780 Content-Type: application/javascript | clean |
http://karenhubert.com/wp-content/themes/Avada/js/jquery.prettyPhoto.js?ver=4.1 | 200 OK Content-Length: 39651 Content-Type: application/javascript | clean |