Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thedominonhomevalues.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cg-dynamics.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Jul 2014 10:11:20 GMT
Accept-Ranges: bytes
ETag: "8cb01e-2e22-4e42976043f77"
Server: Apache
Content-Length: 11810
Content-Type: text/html
Last-Modified: Sat, 17 Aug 2013 19:10:31 GMT
...11810 bytes of data.
GET / HTTP/1.1
Host: cg-dynamics.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 27 Jul 2014 10:11:20 GMT
Accept-Ranges: bytes
ETag: "8cb01e-2e22-4e42976043f77"
Server: Apache
Content-Length: 11810
Content-Type: text/html
Last-Modified: Sat, 17 Aug 2013 19:10:31 GMT
...11810 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cg-dynamics.com
Referer: http://www.google.com/search?q=cg-dynamics.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cg-dynamics.com
Referer: http://www.google.com/search?q=cg-dynamics.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://thedominonhomevalues.com/ | HTTP/1.1 302 Found Cache-Control: no-cache Connection: close Location: http://anasarabia.com Server: nginx/0.7.65 + Phusion Passenger 2.2.5 (mod_rails/mod_rack) Content-Length: 87 Content-Type: text/html; charset=utf-8 P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Status: 302 X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.5 X-Runtime: 5 | malicious |
http://anasarabia.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 10 Jan 2015 14:26:53 GMT Location: http://www.anasarabia.com/ Server: Apache/2.2 Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ahelpkbl=772F4852A27AE0EA6045602F7550F6AE; path=/ | clean |
http://www.anasarabia.com/ | 200 OK Content-Length: 26945 Content-Type: text/html | clean |
http://www.anasarabia.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93128 Content-Type: application/x-javascript | clean |
http://www.anasarabia.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.anasarabia.com/wp-includes/js/comment-reply.min.js?ver=3.6 | 200 OK Content-Length: 786 Content-Type: application/x-javascript | clean |
http://thedominonhomevalues.com/wp-content/plugins/LayerSlider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 | HTTP/1.1 302 Found Cache-Control: no-cache Connection: close Location: http://anasarabia.com/wp-content/plugins/LayerSlider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 Server: nginx/0.7.65 + Phusion Passenger 2.2.5 (mod_rails/mod_rack) Content-Length: 167 Content-Type: text/html; charset=utf-8 P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Status: 302 X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.5 X-Runtime: 23 | malicious |
http://anasarabia.com/wp-content/plugins/layerslider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 10 Jan 2015 14:27:01 GMT Location: http://www.anasarabia.com/wp-content/plugins/layerslider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 Server: Apache/2.2 Content-Length: 381 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ahelpkbl=88F69C474FB314F01E889F9991D13A29; path=/ | clean |
http://www.anasarabia.com/wp-content/plugins/layerslider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 | 404 Not Found Content-Length: 41871 Content-Type: text/html | clean |
http://www.anasarabia.com/wp-content/plugins/LayerSlider/js/layerslider.kreaturamedia.jquery.js?ver=4.1.1 | 200 OK Content-Length: 42005 Content-Type: application/x-javascript | clean |
http://thedominonhomevalues.com/wp-content/plugins/LayerSlider/js/jquery-easing-1.3.js?ver=1.3.0 | HTTP/1.1 302 Found Cache-Control: no-cache Connection: close Location: http://anasarabia.com/wp-content/plugins/LayerSlider/js/jquery-easing-1.3.js?ver=1.3.0 Server: nginx/0.7.65 + Phusion Passenger 2.2.5 (mod_rails/mod_rack) Content-Length: 152 Content-Type: text/html; charset=utf-8 P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Status: 302 X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.5 X-Runtime: 7 | malicious |
http://anasarabia.com/wp-content/plugins/layerslider/js/jquery-easing-1.3.js?ver=1.3.0 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 10 Jan 2015 14:27:05 GMT Location: http://www.anasarabia.com/wp-content/plugins/layerslider/js/jquery-easing-1.3.js?ver=1.3.0 Server: Apache/2.2 Content-Length: 366 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ahelpkbl=BD1F888EA4075B94ED092CCE59CBDDC2; path=/ | clean |
http://www.anasarabia.com/wp-content/plugins/layerslider/js/jquery-easing-1.3.js?ver=1.3.0 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.anasarabia.com/test404page.js | 404 Not Found Content-Length: 41729 Content-Type: text/html | clean |
http://www.anasarabia.com/wp-content/plugins/LayerSlider/js/jquery-easing-1.3.js?ver=1.3.0 | 200 OK Content-Length: 8152 Content-Type: application/x-javascript | clean |
http://www.anasarabia.com/wp-content/plugins/LayerSlider/js/jquerytransit.js?ver=0.9.9 | 200 OK Content-Length: 6565 Content-Type: application/x-javascript | clean |
http://www.anasarabia.com/wp-content/plugins/LayerSlider/js/layerslider.transitions.js?ver=4.1.1 | 200 OK Content-Length: 18334 Content-Type: application/x-javascript | clean |
http://www.anasarabia.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?ver=3.6 | 200 OK Content-Length: 82579 Content-Type: application/x-javascript | clean |
http://maps.google.com/maps/api/js?sensor=false | 200 OK Content-Length: 4357 Content-Type: text/javascript | clean |
http://cdn2.diverse-cdn.com/api/combo-js/config=dsidxpress-pro.js/83a10d | 200 OK Content-Length: 249973 Content-Type: text/javascript | clean |
http://www.anasarabia.com/wp-content/plugins/ct-mortgage-calculator/assets/calc.js?ver=1.0 | 200 OK Content-Length: 523 Content-Type: application/x-javascript | clean |