Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tovendendo.net.br
Result:
GET / HTTP/1.1
Host: tovendendo.net.br
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: tovendendo.net.br
Referer: http://www.google.com/search?q=tovendendo.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tovendendo.net.br
Referer: http://www.google.com/search?q=tovendendo.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.tovendendo.net.br/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.tovendendo.net.br/test404page.js | 404 Not Found Content-Length: 19966 Content-Type: text/html | clean |
http://www.tovendendo.net.br/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: text/javascript | clean |
http://www.tovendendo.net.br/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://www.tovendendo.net.br/wp-content/themes/replete/js/avia.js?ver=4 | HTTP/1.1 302 Found Cache-Control: max-age=600 Connection: close Date: Wed, 04 Mar 2015 16:08:21 GMT Location: http://cloudfront.jfsites.com.br/wp-content/themes/replete/js/avia.js?ver=4 Server: Apache/2.2.29 (Amazon) Content-Length: 346 Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 04 Mar 2015 16:18:21 GMT | clean |
http://cloudfront.jfsites.com.br/wp-content/themes/replete/js/avia.js?ver=4 | 200 OK Content-Length: 89492 Content-Type: text/javascript | clean |
http://jfsites.com.br/?dm=0407ce4acb4005fa9f8e687ec279ccbd&action=load&blogid=7&siteid=1&t=901981690&back=http%3A%2F%2Fwww.tovendendo.net.br%2Ftest404page.js | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://jfsites.com.br/test404page.js | HTTP/1.1 302 Found Cache-Control: private, must-revalidate Connection: close Date: Wed, 04 Mar 2015 16:08:27 GMT Pragma: no-cache Location: http://jfsites.com.br Server: Apache/2.2.29 (Amazon) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=ghq02nvu7ni91590e3ae1jj3h7; path=/ X-Pingback: http://jfsites.com.br/xmlrpc.php X-Powered-By: PHP/5.3.29 | clean |
http://jfsites.com.br/ | 200 OK Content-Length: 11162 Content-Type: text/html | clean |
http://jfsites.com.br/wp-content/themes/jfsites/js/jquery.js | HTTP/1.1 302 Found Cache-Control: private, must-revalidate Connection: close Date: Wed, 04 Mar 2015 16:08:31 GMT Pragma: no-cache Location: http://jfsites.com.br Server: Apache/2.2.29 (Amazon) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=evc1s4fmk00qgvqu6fhopcmal2; path=/ X-Pingback: http://jfsites.com.br/xmlrpc.php X-Powered-By: PHP/5.3.29 | clean |
http://jfsites.com.br/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/slider-pro/js/slider/video.min.js?ver=4.0.1 | 200 OK Content-Length: 63514 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/iphorm-form-builder/js/iphorm.js?ver=1.4.18 | 200 OK Content-Length: 527 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/iphorm-form-builder/js/swfupload.min.js?ver=1.4.18 | 200 OK Content-Length: 31107 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/iphorm-form-builder/js/jquery.iphorm.js?ver=1.4.18 | 200 OK Content-Length: 25508 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/iphorm-form-builder/js/jquery.form.min.js?ver=v20130616 | 200 OK Content-Length: 14510 Content-Type: text/javascript | clean |
http://jfsites.com.br/wp-content/plugins/iphorm-form-builder/js/jquery.smooth-scroll.min.js?ver=1.4.9 | 200 OK Content-Length: 2681 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tovendendo.net.br
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tovendendo.net.br/
Result: tovendendo.net.br is not infected or malware details are not published yet.
Result: tovendendo.net.br is not infected or malware details are not published yet.