Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tour.nocumdodgingallowed.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tour.nocumdodgingallowed.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tour.nocumdodgingallowed.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=315360000
Connection: close
Date: Fri, 10 Oct 2014 12:18:02 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 31 Dec 2037 23:55:55 GMT
X-Powered-By: PHP/5.3.8-pl0-gentoo
GET / HTTP/1.1
Host: tour.nocumdodgingallowed.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=315360000
Connection: close
Date: Fri, 10 Oct 2014 12:18:02 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 31 Dec 2037 23:55:55 GMT
X-Powered-By: PHP/5.3.8-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: tour.nocumdodgingallowed.com
Referer: http://www.google.com/search?q=tour.nocumdodgingallowed.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tour.nocumdodgingallowed.com
Referer: http://www.google.com/search?q=tour.nocumdodgingallowed.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://tour.nocumdodgingallowed.com/ | HTTP/1.1 200 OK Cache-Control: max-age=315360000 Connection: close Date: Fri, 10 Oct 2014 12:18:02 GMT Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 31 Dec 2037 23:55:55 GMT X-Powered-By: PHP/5.3.8-pl0-gentoo | clean |
http://tour.meatmembers.com/a/index1.php | HTTP/1.1 302 Found Cache-Control: max-age=315360000 Connection: close Date: Fri, 10 Oct 2014 12:18:02 GMT Location: http://advidi.optimuum.com/292f0126855ebddf/cd?aff_id=853&aff_sub= Server: nginx Content-Length: 0 Content-Type: text/html Expires: Thu, 31 Dec 2037 23:55:55 GMT | clean |
http://advidi.optimuum.com/292f0126855ebddf/cd?aff_id=853&aff_sub= | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 10 Oct 2014 12:18:02 GMT Location: http://www1.advidi.optimuum.com/292f0126855ebddf/cd?aff_id=853&aff_sub= Server: nginx Content-Length: 154 Content-Type: text/html X-Who: www1 | clean |
http://www1.advidi.optimuum.com/292f0126855ebddf/cd?aff_id=853&aff_sub= | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 10 Oct 2014 12:18:02 GMT Location: http://insanetrack.com/?c=13130&a=853&s1=&s5=VID-DvN3aDqrWHbqEk4wd2IkVw%3D%3D-dcGSCS0U%2FzRZL6KS7ZwOxg%3D%3D-1412943482 Server: nginx Content-Length: 0 Content-Type: text/html;charset=utf-8 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Who: www1 X-XSS-Protection: 1; mode=block | clean |
http://insanetrack.com/?c=13130&a=853&s1=&s5=vid-dvn3adqrwhbqek4wd2ikvw%3d%3d-dcgscs0u%2fzrzl6ks7zwoxg%3d%3d-1412943482 | HTTP/1.1 302 Found Cache-Control: private Date: Fri, 10 Oct 2014 12:18:00 GMT Location: http://www.fling.com/enter.php?prg=1&t=zbigvid5&id=advidi&cmp=123571277&ad_id=853 Server: Microsoft-IIS/8.0 Content-Length: 214 Content-Type: text/html; charset=utf-8 P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Set-Cookie: .sess=i2f1pdyimmwpiohzkwpzj443; path=/; HttpOnly Set-Cookie: sid=hgC0Uo8kXa5M9+Fni4u98VgZiYSf2OzE2Zxi9YxlvQSbuYmlWKEaLg==; domain=.insanetrack.com; path=/; HttpOnly Set-Cookie: trk=y0OISpum1DdpLkkwMzlN/FgZiYSf2OzE2Zxi9YxlvQSbuYmlWKEaLg==; domain=.insanetrack.com; expires=Thu, 10-Oct-2019 12:18:01 GMT; path=/; HttpOnly Set-Cookie: c4=hgC0Uo8kXa7GTn/00aczvvqGAADK+WgU3SOHO7cOUcar4AaRmzbZlQ==; domain=.insanetrack.com; expires=Sun, 09-Nov-2014 13:18:01 GMT; path=/; HttpOnly X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://www.fling.com/enter.php?prg=1&t=zbigvid5&id=advidi&cmp=123571277&ad_id=853 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 12:18:03 GMT Location: /tour/zbigvid5/?prg=1&id=advidi&tour=zbigvid5&ot=zbigvid5&cmp=123571277&ad_id=853&utm_source=advidi&utm_medium=123571277&utm_content=853&utm_campaign=zbigvid5 Server: nginx Content-Type: text/html; charset=utf-8 Set-Cookie: l10n_lang=en; expires=Fri, 07-Nov-2014 12:18:03 GMT; path=/; domain=.fling.com Set-Cookie: ps7_crumb=W1siMSIsImFkdmlkaSIsIjIwMTQtMTAtMTAiLCI4NTMiLCIxMjM1NzEyNzciXV0%3D; expires=Sat, 10-Oct-2015 12:18:03 GMT; path=/; domain=.fling.com Set-Cookie: mobile_settings=a%3A1%3A%7Bs%3A6%3A%22isipad%22%3Bb%3A0%3B%7D; path=/; domain=.fling.com Set-Cookie: mobile_settings=a%3A1%3A%7Bs%3A11%3A%22isandroidos%22%3Bb%3A0%3B%7D; path=/; domain=.fling.com Set-Cookie: mobile_settings=a%3A1%3A%7Bs%3A7%3A%22default%22%3Bb%3A0%3B%7D; path=/; domain=.fling.com Set-Cookie: fl_ref_url=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.fling.com | clean |
http://www.fling.com/test404page.js | 200 OK Content-Length: 49866 Content-Type: text/html | clean |
http://cachewp.fling.com/js/1400260746/index_page.js | 200 OK Content-Length: 6896 Content-Type: application/x-javascript | clean |
http://www.fling.com/js/jquery.js | 200 OK Content-Length: 96837 Content-Type: application/x-javascript | clean |
http://cachewp.fling.com/js/1405672159/public.js | 200 OK Content-Length: 98576 Content-Type: application/x-javascript | clean |
http://www.fling.com/tour/js/jquery.colorbox.js | 200 OK Content-Length: 27813 Content-Type: application/x-javascript | clean |
http://cachewp.fling.com/tour/js/jquery.cycle.all.js | 200 OK Content-Length: 36449 Content-Type: application/x-javascript | clean |
https://mpsnare.iesnare.com/snare.js | 200 OK Content-Length: 35712 Content-Type: text/javascript | clean |
http://www.fling.com/js/static_wdp.js | 200 OK Content-Length: 30899 Content-Type: application/x-javascript | clean |
http://www.fling.com/iojs/4.1.1/dyn_wdp.js | 201 Created Content-Length: 1085 Content-Type: text/javascript | clean |
http://www.fling.com/ | 200 OK Content-Length: 49876 Content-Type: text/html | clean |
http://www.fling.com/main.php?a=user.forgotpassword | 200 OK Content-Length: 12928 Content-Type: text/html | clean |
http://www.fling.com/members/user/register | 200 OK Content-Length: 14643 Content-Type: text/html | clean |
http://cachewp.fling.com/js/1405672159/registration.js | 200 OK Content-Length: 105439 Content-Type: application/x-javascript | clean |
http://www.fling.com/main.php?a=user.login | 200 OK Content-Length: 12798 Content-Type: text/html | clean |
http://www.fling.com/members/user/register?p=home | 200 OK Content-Length: 14552 Content-Type: text/html | clean |