Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=titou.biz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://titou.biz/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: titou.biz
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 25 May 2014 14:32:01 GMT
Server: LiteSpeed
Content-Type: text/html; charset=UTF-8
Set-Cookie: wordpress_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C4fb376305867fb1aaa977d65ede450ab; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C4fb376305867fb1aaa977d65ede450ab; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C7cca5a72658ed03360efff584e039e3e; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/; httponly
X-Pingback: http://titou.biz/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: titou.biz
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 25 May 2014 14:32:01 GMT
Server: LiteSpeed
Content-Type: text/html; charset=UTF-8
Set-Cookie: wordpress_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C4fb376305867fb1aaa977d65ede450ab; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C4fb376305867fb1aaa977d65ede450ab; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_8615c99e847833e83e195e2361c680d4=%7C1402237921%7C7cca5a72658ed03360efff584e039e3e; expires=Mon, 09-Jun-2014 02:32:01 GMT; path=/; httponly
X-Pingback: http://titou.biz/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: titou.biz
Referer: http://www.google.com/search?q=titou.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: titou.biz
Referer: http://www.google.com/search?q=titou.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://titou.biz/ | 200 OK Content-Length: 27937 Content-Type: text/html | clean |
http://cdn.popcash.net/pop.js | 200 OK Content-Length: 2864 Content-Type: application/x-javascript | clean |
http://yllix.com/popup.php?pub=153212§ion=General&ga=a | 200 OK Content-Length: 529 Content-Type: text/html | clean |
http://yllix.com/ | 200 OK Content-Length: 13198 Content-Type: text/html | clean |
http://static3.yx-img.com/js/jquery-1.7.2.min.js | 200 OK Content-Length: 94840 Content-Type: application/x-javascript | clean |
http://yllix.com/fancybox/jquery.fancybox-1.3.4.pack.js | 200 OK Content-Length: 15624 Content-Type: application/x-javascript | clean |
http://static4.yx-img.com/js/slides.jquery.js | 200 OK Content-Length: 18635 Content-Type: application/x-javascript | clean |
http://static1.yx-img.com/js/jquery.flexislider.js | 200 OK Content-Length: 1201 Content-Type: application/x-javascript | clean |
http://static2.yx-img.com/js/jquery.tipsy.js | 200 OK Content-Length: 9787 Content-Type: application/x-javascript | clean |
http://yllix.com/publishers/ | 200 OK Content-Length: 10788 Content-Type: text/html | clean |
http://yllix.com/advertisers/ | 200 OK Content-Length: 10861 Content-Type: text/html | clean |
http://yllix.com/faq/ | 200 OK Content-Length: 11642 Content-Type: text/html | clean |
http://yllix.com/contact/ | 200 OK Content-Length: 9459 Content-Type: text/html | clean |
http://yllix.com/login_box/ | 200 OK Content-Length: 428 Content-Type: text/html | clean |
http://yllix.com/test404page.js | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |