Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: wilkescoins.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Date: Sat, 04 Oct 2014 20:42:26 GMT
Location: http://wilkesandcurtis.com
Server: Microsoft-IIS/7.5
Content-Length: 0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...0 bytes of data.
GET / HTTP/1.1
Host: wilkescoins.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Date: Sat, 04 Oct 2014 20:42:26 GMT
Location: http://wilkesandcurtis.com
Server: Microsoft-IIS/7.5
Content-Length: 0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: wilkescoins.com
Referer: http://www.google.com/search?q=wilkescoins.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: wilkescoins.com
Referer: http://www.google.com/search?q=wilkescoins.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://wilkescoins.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: private Date: Sat, 04 Oct 2014 20:42:26 GMT Location: http://wilkesandcurtis.com Server: Microsoft-IIS/7.5 Content-Length: 0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://wilkesandcurtis.com/ | 200 OK Content-Length: 10662 Content-Type: text/html | clean |
http://wilkesandcurtis.com/misc/jquery.js?v=1.4.4 | 200 OK Content-Length: 78602 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/misc/jquery.once.js?v=1.2 | 200 OK Content-Length: 2974 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/misc/drupal.js?na5abf | 200 OK Content-Length: 14544 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/jquery.flexslider.js?na5abf | 200 OK Content-Length: 40487 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/slide.js?na5abf | 200 OK Content-Length: 146 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/bootstrap.min.js?na5abf | 200 OK Content-Length: 27242 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/superfish.js?na5abf | 200 OK Content-Length: 3083 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/mobilemenu.js?na5abf | 200 OK Content-Length: 2052 Content-Type: application/javascript | clean |
http://wilkesandcurtis.com/sites/all/themes/nexus/js/custom.js?na5abf | 200 OK Content-Length: 1115 Content-Type: application/javascript | clean |
http://wilkescoins.com/node/5 | HTTP/1.1 301 Moved Permanently Cache-Control: private Date: Sat, 04 Oct 2014 20:42:32 GMT Location: http://wilkesandcurtis.com/node/5 Server: Microsoft-IIS/7.5 Content-Length: 0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://wilkesandcurtis.com/node/5 | 200 OK Content-Length: 10525 Content-Type: text/html | clean |
http://wilkesandcurtis.com/node/6 | 200 OK Content-Length: 13121 Content-Type: text/html | clean |
http://wilkesandcurtis.com/node/7 | 200 OK Content-Length: 9268 Content-Type: text/html | clean |
http://wilkesandcurtis.com/node/9 | 200 OK Content-Length: 10167 Content-Type: text/html | clean |
http://wilkesandcurtis.com/node/2 | 200 OK Content-Length: 10814 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=wilkescoins.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://wilkescoins.com/
Result: wilkescoins.com is not infected or malware details are not published yet.
Result: wilkescoins.com is not infected or malware details are not published yet.