Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gefosat.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Thu, 17 Dec 2015 09:26:36 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 90planBAK=R698939582; path=/; expires=Thu, 17-Dec-2015 10:25:18 GMT
Set-Cookie: 90plan=R1531004838; path=/; expires=Thu, 17-Dec-2015 10:25:49 GMT
Set-Cookie: crawlprotecttag=present; expires=Fri, 18-Dec-2015 09:26:36 GMT; path=/
Set-Cookie: 6fd1d5d48a4aefd2b0f915530f73fabc=mohqmudr3j6lvec5qjqc601p06; path=/
X-Cacheable: Not cacheable: no-cache
X-Geo: varn03.rbx5
X-Geo-Port: 1002
GET / HTTP/1.1
Host: gefosat.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Thu, 17 Dec 2015 09:26:36 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 90planBAK=R698939582; path=/; expires=Thu, 17-Dec-2015 10:25:18 GMT
Set-Cookie: 90plan=R1531004838; path=/; expires=Thu, 17-Dec-2015 10:25:49 GMT
Set-Cookie: crawlprotecttag=present; expires=Fri, 18-Dec-2015 09:26:36 GMT; path=/
Set-Cookie: 6fd1d5d48a4aefd2b0f915530f73fabc=mohqmudr3j6lvec5qjqc601p06; path=/
X-Cacheable: Not cacheable: no-cache
X-Geo: varn03.rbx5
X-Geo-Port: 1002
Second query (visit from search engine):
GET / HTTP/1.1
Host: gefosat.org
Referer: http://www.google.com/search?q=gefosat.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gefosat.org
Referer: http://www.google.com/search?q=gefosat.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gefosat.org/ | 200 OK Content-Length: 33134 Content-Type: text/html | clean |
http://gefosat.org/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://gefosat.org/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://gefosat.org/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
http://gefosat.org/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: application/javascript | clean |
http://gefosat.org/modules/mod_news_pro_gk4/interface/scripts/engine.js | 200 OK Content-Length: 8034 Content-Type: application/javascript | clean |
http://gefosat.org/media/com_acymailing/js/acymailing_module.js?v=462 | 200 OK Content-Length: 14287 Content-Type: application/javascript | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.js | 200 OK Content-Length: 93435 Content-Type: text/javascript | clean |
http://gefosat.org/modules/mod_iccalendar/js/jquery.noconflict.js | 200 OK Content-Length: 20 Content-Type: application/javascript | clean |
http://gefosat.org/templates/gefosat/jquery.js | 200 OK Content-Length: 92793 Content-Type: application/javascript | clean |
http://gefosat.org/templates/gefosat/script.js | 200 OK Content-Length: 46109 Content-Type: application/javascript | clean |
http://gefosat.org/templates/gefosat/script.responsive.js | 200 OK Content-Length: 15939 Content-Type: application/javascript | clean |
http://gefosat.org/index.php/accueil/notre-association | 200 OK Content-Length: 33178 Content-Type: text/html | clean |
http://gefosat.org/index.php/accueil/l-equipe | 200 OK Content-Length: 31321 Content-Type: text/html | clean |
http://gefosat.org/index.php/accueil/adherer-et-soutenir-gefosat | 200 OK Content-Length: 33334 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gefosat.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gefosat.org/
Result: gefosat.org is not infected or malware details are not published yet.
Result: gefosat.org is not infected or malware details are not published yet.