Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trattoriatoscanamartino.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 04 Oct 2014 18:32:48 GMT
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 2324
Content-Type: text/html
Set-Cookie: uid=trattoriatoscanamartino54303d500cc7e6.05918147; expires=Mon, 03-Nov-2014 18:32:48 GMT
Set-Cookie: WEBUK=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANHZLSNGAhe0lWbSycFlY7t3c4tFHP+Epw8naGgm3CR8CftAihnB7Jkt+vFmvIf3BV/p3RpOrZ/XbZsX9uh0m9UCAwEAAQ==_DRP4lD0mqtJMcP9DquAxh2MTs9fDFrAJRrKp/MFKEh4KRA1uIMHA7X+yu8eIwf7kgmFifmrM4YiJYFTmNpUCtA==
X-Powered-By: PHP/5.3.10-1ubuntu3.9
...2324 bytes of data.
GET / HTTP/1.1
Host: trattoriatoscanamartino.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 04 Oct 2014 18:32:48 GMT
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 2324
Content-Type: text/html
Set-Cookie: uid=trattoriatoscanamartino54303d500cc7e6.05918147; expires=Mon, 03-Nov-2014 18:32:48 GMT
Set-Cookie: WEBUK=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANHZLSNGAhe0lWbSycFlY7t3c4tFHP+Epw8naGgm3CR8CftAihnB7Jkt+vFmvIf3BV/p3RpOrZ/XbZsX9uh0m9UCAwEAAQ==_DRP4lD0mqtJMcP9DquAxh2MTs9fDFrAJRrKp/MFKEh4KRA1uIMHA7X+yu8eIwf7kgmFifmrM4YiJYFTmNpUCtA==
X-Powered-By: PHP/5.3.10-1ubuntu3.9
...2324 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: trattoriatoscanamartino.com
Referer: http://www.google.com/search?q=trattoriatoscanamartino.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trattoriatoscanamartino.com
Referer: http://www.google.com/search?q=trattoriatoscanamartino.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://trattoriatoscanamartino.com/ | 200 OK Content-Length: 2324 Content-Type: text/html | clean |
http://return.uk.domainnamesales.com/return_js.php?d=trattoriatoscanamartino.com&s=1412447568 | 200 OK Content-Length: 1557 Content-Type: text/html | clean |
http://return.uk.domainnamesales.com/test404page.js | 200 OK Content-Length: 1557 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js | 200 OK Content-Length: 85925 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trattoriatoscanamartino.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://trattoriatoscanamartino.com/
Result: trattoriatoscanamartino.com is not infected or malware details are not published yet.
Result: trattoriatoscanamartino.com is not infected or malware details are not published yet.