Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=weddingdecoration.md
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: weddingdecoration.md
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 14 Jan 2015 07:21:59 GMT
Accept-Ranges: bytes
ETag: "52002-85a8-50c9365ba7e80"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 34216
Content-Type: text/html
Last-Modified: Wed, 14 Jan 2015 02:21:30 GMT
...34216 bytes of data.
GET / HTTP/1.1
Host: weddingdecoration.md
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 14 Jan 2015 07:21:59 GMT
Accept-Ranges: bytes
ETag: "52002-85a8-50c9365ba7e80"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 34216
Content-Type: text/html
Last-Modified: Wed, 14 Jan 2015 02:21:30 GMT
...34216 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: weddingdecoration.md
Referer: http://www.google.com/search?q=weddingdecoration.md
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: weddingdecoration.md
Referer: http://www.google.com/search?q=weddingdecoration.md
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://weddingdecoration.md/ | 200 OK Content-Length: 34216 Content-Type: text/html | clean |
http://23.236.64.18/mb/js.js | 200 OK Content-Length: 646 Content-Type: application/x-javascript | clean |
http://js.users.51.la/17605496.js | 200 OK Content-Length: 1964 Content-Type: application/x-javascript | clean |
http://weddingdecoration.md/test404page.js | HTTP/1.1 302 Found Connection: close Date: Wed, 14 Jan 2015 07:22:01 GMT Location: http://pharmacy-2015.com/ Server: Apache/2.2.22 (Ubuntu) Vary: Accept-Encoding Content-Length: 295 Content-Type: text/html; charset=iso-8859-1 | clean |
http://pharmacy-2015.com/ | HTTP/1.1 302 Found Connection: close Date: Wed, 14 Jan 2015 07:22:01 GMT Location: http://magicgenericservice.com Server: nginx/1.6.2 Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3 | clean |
http://magicgenericservice.com/ | 403 Forbidden Content-Length: 168 Content-Type: text/html | clean |
http://magicgenericservice.com/test404page.js | 403 Forbidden Content-Length: 168 Content-Type: text/html | clean |