Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: weldwheels.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 14 Jan 2015 11:38:36 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=vv2smt4v4sf5k215k9vps7d6r0; path=/
X-Pingback: http://weldwheels.com/xmlrpc.php
X-Powered-By: PHP/5.4.31
GET / HTTP/1.1
Host: weldwheels.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 14 Jan 2015 11:38:36 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=vv2smt4v4sf5k215k9vps7d6r0; path=/
X-Pingback: http://weldwheels.com/xmlrpc.php
X-Powered-By: PHP/5.4.31
Second query (visit from search engine):
GET / HTTP/1.1
Host: weldwheels.com
Referer: http://www.google.com/search?q=weldwheels.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: weldwheels.com
Referer: http://www.google.com/search?q=weldwheels.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://weldwheels.com/ | 200 OK Content-Length: 90656 Content-Type: text/html | clean |
http://weldwheels.com/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7199 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/jquery.tmpl.min.js?ver=4.0.1 | 200 OK Content-Length: 6007 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/jquery.easing.1.3.js?ver=1.3 | 200 OK Content-Length: 8097 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/jquery.elastislide.js?ver=4.0.1 | 200 OK Content-Length: 13007 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/jquery.selectbox-0.5.js?ver=0.5 | 200 OK Content-Length: 5320 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/gallery.js?ver=4.0.1 | 200 OK Content-Length: 6484 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/themes/weld/js/custom.js?ver=4.0.1 | 200 OK Content-Length: 1205 Content-Type: text/javascript | clean |
http://weldwheels.com/dealer-locator/ | 200 OK Content-Length: 33828 Content-Type: text/html | clean |
http://maps.google.com/maps/api/js?sensor=false&language=en&ver=4.2.08 | 200 OK Content-Length: 4236 Content-Type: text/javascript | clean |
http://weldwheels.com/wp-content/plugins/store-locator-le/js/slp.js?ver=4.2.08 | 200 OK Content-Length: 63285 Content-Type: text/javascript | clean |
http://weldwheels.com/shop/checkout/cart/ | 200 OK Content-Length: 44388 Content-Type: text/html | clean |
http://weldwheels.com/shop/js/prototype/prototype.js | 200 OK Content-Length: 163313 Content-Type: text/javascript | clean |
http://weldwheels.com/shop/js/lib/ccard.js | 200 OK Content-Length: 747 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=weldwheels.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://weldwheels.com/
Result: weldwheels.com is not infected or malware details are not published yet.
Result: weldwheels.com is not infected or malware details are not published yet.