Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=vahidblog.ir
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://vahidblog.ir/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://vahidblog.ir/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=0 Connection: close Date: Fri, 01 Aug 2014 22:42:05 GMT Location: http://www.vahidblog.ir/ Server: Apache Vary: User-Agent,Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Aug 2014 22:42:05 GMT X-Pingback: http://www.vahidblog.ir/xmlrpc.php X-Powered-By: PHP/5.3.27 | clean |
http://www.vahidblog.ir/ | 200 OK Content-Length: 62245 Content-Type: text/html | clean |
http://www.vahidblog.ir/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://www.vahidblog.ir/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.vahidblog.ir/wp-content/themes/hotnews/javascripts/plugins.js?ver=1.0.2 | 200 OK Content-Length: 77788 Content-Type: application/javascript | clean |
http://www.vahidblog.ir/wp-content/themes/hotnews/javascripts/jquery.sharrre-1.3.3.min.js?ver=1.0.2 | 200 OK Content-Length: 10041 Content-Type: application/javascript | clean |
http://static.hupso.com/share/js/share_toolbar.js | 200 OK Content-Length: 5872 Content-Type: application/x-javascript | clean |
http://4030.tbuy.biz/shop/ads/popup/4545/0 | 200 OK Content-Length: 712 Content-Type: text/html | clean |
http://4030.tbuy.biz/test404page.js | 404 Not Found Content-Length: 2129 Content-Type: text/html | clean |
http://4030.tbuy.biz/js/j1.8.js | 200 OK Content-Length: 93436 Content-Type: application/x-javascript | clean |
http://4030.tbuy.biz/ | 200 OK Content-Length: 40042 Content-Type: text/html | clean |
http://www.persianstat.com/service/stat.js | 200 OK Content-Length: 6631 Content-Type: application/x-javascript | clean |
http://www.webgozar.ir/c.aspx?Code=3041322&t=counter | 200 OK Content-Length: 973 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 0x0 src: http://engine.webgozar.ir/counter/xstat.aspx?t=stat5&code=3041322&rnd= <iframe scrolling=no width=0 height=0 border=0 frameborder=0 allowtransparency="true" src="http://engine.webgozar.ir/counter/xstat.aspx?t=stat5&code=3041322&rnd=' + math.round(math.random()*50000) + '&s=' + screensize + '&c=' + colors + '&ref=' + escape(document.referrer) + '&title=' + escape(document.title) + '" > | ||
http://www.webgozar.ir/test404page.js | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |
http://4030.tbuy.biz/blog/posts/view/44 | 200 OK Content-Length: 22349 Content-Type: text/html | clean |
http://4030.tbuy.biz/blog/posts/view/46 | 200 OK Content-Length: 24028 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: vahidblog.ir
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0
Connection: close
Date: Fri, 01 Aug 2014 22:42:05 GMT
Location: http://www.vahidblog.ir/
Server: Apache
Vary: User-Agent,Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Fri, 01 Aug 2014 22:42:05 GMT
X-Pingback: http://www.vahidblog.ir/xmlrpc.php
X-Powered-By: PHP/5.3.27
...0 bytes of data.
GET / HTTP/1.1
Host: vahidblog.ir
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0
Connection: close
Date: Fri, 01 Aug 2014 22:42:05 GMT
Location: http://www.vahidblog.ir/
Server: Apache
Vary: User-Agent,Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Fri, 01 Aug 2014 22:42:05 GMT
X-Pingback: http://www.vahidblog.ir/xmlrpc.php
X-Powered-By: PHP/5.3.27
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: vahidblog.ir
Referer: http://www.google.com/search?q=vahidblog.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: vahidblog.ir
Referer: http://www.google.com/search?q=vahidblog.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.