Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thecandlemakersstore.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Cache-Control: public, max-age=31536000
Connection: close
Date: Tue, 13 Jan 2015 22:15:57 GMT
Pragma: no-cache
Server: LiteSpeed
Vary: User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Expires: Wed, 13 Jan 2016 22:15:57 GMT
Set-Cookie: frontend=ofk8i0gjjlbkt37bbr1e9rmuk0; expires=Sun, 18-Jan-2015 22:15:56 GMT; path=/; domain=thecandlemakersstore.com; HttpOnly
GET / HTTP/1.1
Host: thecandlemakersstore.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Cache-Control: public, max-age=31536000
Connection: close
Date: Tue, 13 Jan 2015 22:15:57 GMT
Pragma: no-cache
Server: LiteSpeed
Vary: User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Expires: Wed, 13 Jan 2016 22:15:57 GMT
Set-Cookie: frontend=ofk8i0gjjlbkt37bbr1e9rmuk0; expires=Sun, 18-Jan-2015 22:15:56 GMT; path=/; domain=thecandlemakersstore.com; HttpOnly
Second query (visit from search engine):
GET / HTTP/1.1
Host: thecandlemakersstore.com
Referer: http://www.google.com/search?q=thecandlemakersstore.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thecandlemakersstore.com
Referer: http://www.google.com/search?q=thecandlemakersstore.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://thecandlemakersstore.com/ | 200 OK Content-Length: 62512 Content-Type: text/html | clean |
https://use.typekit.com/psn3wsb.js | 200 OK Content-Length: 30182 Content-Type: text/javascript | clean |
http://thecandlemakersstore.com/media/js/ad75cbc21cef44317fb414d99e54d222.js | 200 OK Content-Length: 300153 Content-Type: application/javascript | clean |
http://thecandlemakersstore.com//www.googleadservices.com/pagead/conversion.js/ | 404 Not Found Content-Length: 57218 Content-Type: text/html | clean |
http://thecandlemakersstore.com//verify.authorize.net/anetseal/seal.js/ | 404 Not Found Content-Length: 57218 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making.html | 200 OK Content-Length: 75167 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-additives.html | 200 OK Content-Length: 77812 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-color-dye.html | 200 OK Content-Length: 73940 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-fragrances.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 13 Jan 2015 22:16:16 GMT Location: http://thecandlemakersstore.com/fragrances.html Server: LiteSpeed Vary: User-Agent Content-Length: 1172 Content-Type: text/html | clean |
http://thecandlemakersstore.com/fragrances.html | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://thecandlemakersstore.com/test404page.js | 404 Not Found Content-Length: 57218 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-jars-molds.html | 200 OK Content-Length: 93260 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-jars-molds/apothecary-with-flat-glass-lid.html | 200 OK Content-Length: 78402 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-jars-molds/apothecary-with-globe-lid.html | 200 OK Content-Length: 78147 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-jars-molds/apothecary-with-wood-lid.html | 200 OK Content-Length: 78344 Content-Type: text/html | clean |
http://thecandlemakersstore.com/candle-making/candle-making-jars-molds/classic-jar.html | 200 OK Content-Length: 79292 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thecandlemakersstore.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://thecandlemakersstore.com/
Result: thecandlemakersstore.com is not infected or malware details are not published yet.
Result: thecandlemakersstore.com is not infected or malware details are not published yet.