Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: top-locksmith.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Sun, 05 Oct 2014 02:25:36 GMT
Location: http://www.top-locksmith.com/
Server: Microsoft-IIS/6.0
Content-Length: 152
Content-Type: text/html
X-Powered-By: ASP.NET
...152 bytes of data.
GET / HTTP/1.1
Host: top-locksmith.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Sun, 05 Oct 2014 02:25:36 GMT
Location: http://www.top-locksmith.com/
Server: Microsoft-IIS/6.0
Content-Length: 152
Content-Type: text/html
X-Powered-By: ASP.NET
...152 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: top-locksmith.com
Referer: http://www.google.com/search?q=top-locksmith.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: top-locksmith.com
Referer: http://www.google.com/search?q=top-locksmith.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://top-locksmith.com/ | HTTP/1.1 301 Moved Permanently Date: Sun, 05 Oct 2014 02:25:36 GMT Location: http://www.top-locksmith.com/ Server: Microsoft-IIS/6.0 Content-Length: 152 Content-Type: text/html X-Powered-By: ASP.NET | clean |
http://www.top-locksmith.com/ | 200 OK Content-Length: 16183 Content-Type: text/html | clean |
http://www.top-locksmith.com/frmCheck.js | HTTP/1.1 200 OK Date: Sun, 05 Oct 2014 02:25:38 GMT Accept-Ranges: bytes ETag: "584a2ce9ecc91:916" Server: Microsoft-IIS/6.0 Content-Length: 6625 Content-Location: http://www.top-locksmith.com/frmCheck.js Content-Type: application/x-javascript Last-Modified: Sun, 14 Jun 2009 12:10:57 GMT X-Powered-By: ASP.NET | clean |
http://www.top-locksmith.com/frmcheck.js | HTTP/1.1 200 OK Date: Sun, 05 Oct 2014 02:25:38 GMT Accept-Ranges: bytes ETag: "584a2ce9ecc91:916" Server: Microsoft-IIS/6.0 Content-Length: 6625 Content-Location: http://www.top-locksmith.com/frmcheck.js Content-Type: application/x-javascript Last-Modified: Sun, 14 Jun 2009 12:10:57 GMT X-Powered-By: ASP.NET | clean |
http://www.top-locksmith.com/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://top-locksmith.com/validation.js | HTTP/1.1 301 Moved Permanently Date: Sun, 05 Oct 2014 02:25:39 GMT Location: http://www.top-locksmith.com/validation.js Server: Microsoft-IIS/6.0 Content-Length: 165 Content-Type: text/html X-Powered-By: ASP.NET | clean |
http://www.top-locksmith.com/validation.js | HTTP/1.1 200 OK Date: Sun, 05 Oct 2014 02:25:39 GMT Accept-Ranges: bytes ETag: "bdc7747e9ecc91:916" Server: Microsoft-IIS/6.0 Content-Length: 2110 Content-Location: http://www.top-locksmith.com/validation.js Content-Type: application/x-javascript Last-Modified: Sun, 14 Jun 2009 12:11:42 GMT X-Powered-By: ASP.NET | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=top-locksmith.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://top-locksmith.com/
Result: top-locksmith.com is not infected or malware details are not published yet.
Result: top-locksmith.com is not infected or malware details are not published yet.