Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: whexever.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 17:08:00 GMT
Location: http://www.whexever.com/
Server: nginx/1.6.2
Content-Length: 294
Content-Type: text/html; charset=iso-8859-1
...294 bytes of data.
GET / HTTP/1.1
Host: whexever.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 17:08:00 GMT
Location: http://www.whexever.com/
Server: nginx/1.6.2
Content-Length: 294
Content-Type: text/html; charset=iso-8859-1
...294 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: whexever.com
Referer: http://www.google.com/search?q=whexever.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: whexever.com
Referer: http://www.google.com/search?q=whexever.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://whexever.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:00 GMT Location: http://www.whexever.com/ Server: nginx/1.6.2 Content-Length: 294 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.whexever.com/ | 200 OK Content-Length: 9484 Content-Type: text/html | clean |
http://www.whexever.com/recursos/word_tip.js | 200 OK Content-Length: 3532 Content-Type: application/javascript | clean |
http://whexever.com/page/nosotros.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:04 GMT Location: http://www.whexever.com/page/nosotros.html Server: nginx/1.6.2 Content-Length: 312 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.whexever.com/page/nosotros.html | 200 OK Content-Length: 7945 Content-Type: text/html | clean |
http://www.whexever.com/page/contacto.html | 200 OK Content-Length: 11219 Content-Type: text/html | clean |
http://www.google.com/recaptcha/api/challenge?k=6LeRZtcSAAAAAKHp8Nu4Tnephej0NpsK8O7RJTpQ | 200 OK Content-Length: 10567 Content-Type: text/javascript | clean |
http://www.whexever.com/page/politica-de-privacidad.html | 200 OK Content-Length: 8498 Content-Type: text/html | clean |
http://www.whexever.com/page/condiciones-de-servicio.html | 200 OK Content-Length: 10846 Content-Type: text/html | clean |
http://www.whexever.com/page/tarifas.html | 200 OK Content-Length: 7902 Content-Type: text/html | clean |
http://www.whexever.com/page/servicios.html | 200 OK Content-Length: 7751 Content-Type: text/html | clean |
http://www.whexever.com/test404page.js | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://suspended.hostgator.com/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
http://whexever.com/page/politica-de-privacidad.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:12 GMT Location: http://www.whexever.com/page/politica-de-privacidad.html Server: nginx/1.6.2 Content-Length: 326 Content-Type: text/html; charset=iso-8859-1 | clean |
http://whexever.com/page/condiciones-de-servicio.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:13 GMT Location: http://www.whexever.com/page/condiciones-de-servicio.html Server: nginx/1.6.2 Content-Length: 327 Content-Type: text/html; charset=iso-8859-1 | clean |
http://whexever.com/page/tarifas.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:14 GMT Location: http://www.whexever.com/page/tarifas.html Server: nginx/1.6.2 Content-Length: 311 Content-Type: text/html; charset=iso-8859-1 | clean |
http://whexever.com/page/servicios.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:14 GMT Location: http://www.whexever.com/page/servicios.html Server: nginx/1.6.2 Content-Length: 313 Content-Type: text/html; charset=iso-8859-1 | clean |
http://whexever.com/indice/a | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:08:15 GMT Location: http://www.whexever.com/indice/a Server: nginx/1.6.2 Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.whexever.com/indice/a | 200 OK Content-Length: 23733 Content-Type: text/html | clean |
http://www.whexever.com/www/a-alvarez.com | 200 OK Content-Length: 16650 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21308 Content-Type: text/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=whexever.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://whexever.com/
Result: whexever.com is not infected or malware details are not published yet.
Result: whexever.com is not infected or malware details are not published yet.