Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://welcomesydney.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: welcomesydney.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sun, 26 Jul 2015 15:52:17 GMT Location: http://clcktrck.net/path/lp.php?trvid=10003&trvx=3721aa50&search=welcomesydney.com&smid=dCewkW9F&dom=welcomesydney.com Server: cloudflare-nginx Content-Type: text/html;charset=UTF-8 CF-RAY: 20c1455444510aea-WAW Set-Cookie: __cfduid=dcc3ab5f09cc2e2e277c31df5d91213f61437925937; expires=Mon, 25-Jul-16 15:52:17 GMT; path=/; domain=.welcomesydney.com; HttpOnly | malicious |
URL: http://clcktrck.net/path/lp.php?trvid=10003&trvx=3721aa50&search=welcomesydney.com&smid=dCewkW9F&dom=welcomesydney.com (imitation of visitor from search engine) GET /path/lp.php?trvid=10003&trvx=3721aa50&search=welcomesydney.com&smid=dCewkW9F&dom=welcomesydney.com HTTP/1.1 Host: clcktrck.net Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 26 Jul 2015 15:52:18 GMT Pragma: no-cache Location: http://www.dietreport.net/garcinia-cambogia/international.php?oid=1023&sxid=o933jv27b5u7 Server: Apache Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: THRIVE_SESS=vtsjk2pae0f50jp584j278pgi6; path=/; domain=.clcktrck.net; HttpOnly Set-Cookie: ClickId=o933jv27b5u7; expires=Tue, 25-Aug-2015 15:52:18 GMT; path=/; domain=.clcktrck.net Set-Cookie: OfferPage=http%3A%2F%2Faffiliate.gmtracker.com%2Frd%2Fr.php%3Fsid%3D3601%26pub%3D301252%26c1%3Do933jv27b5u7%26c2%3D%26c3%3D; expires=Tue, 25-Aug-2015 15:52:18 GMT; path=/; domain=.clcktrck.net X-Powered-By: PHP/5.4.16 X-UA-Compatible: IE=Edge,chrome=1 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://welcomesydney.com/ | 200 OK Content-Length: 155 Content-Type: text/html | clean |
http://welcomesydney.com/test404page.js | 200 OK Content-Length: 155 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=welcomesydney.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://welcomesydney.com/
Result: welcomesydney.com is not infected or malware details are not published yet.
Result: welcomesydney.com is not infected or malware details are not published yet.