Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: laia.lt
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 23 Jun 2014 23:32:17 GMT
Location: http://www.laia.lt/
Server: cloudflare-nginx
Content-Type: text/html; charset=UTF-8
Alternate-Protocol: 80:quic
CF-RAY: 13f47beac3e50899-FRA
Set-Cookie: __cfduid=d9f14e0ba413b6d69fc202834486493f11403566337721; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
GET / HTTP/1.1
Host: laia.lt
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 23 Jun 2014 23:32:17 GMT
Location: http://www.laia.lt/
Server: cloudflare-nginx
Content-Type: text/html; charset=UTF-8
Alternate-Protocol: 80:quic
CF-RAY: 13f47beac3e50899-FRA
Set-Cookie: __cfduid=d9f14e0ba413b6d69fc202834486493f11403566337721; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Second query (visit from search engine):
GET / HTTP/1.1
Host: laia.lt
Referer: http://www.google.com/search?q=laia.lt
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: laia.lt
Referer: http://www.google.com/search?q=laia.lt
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://laia.lt/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 23 Jun 2014 23:32:17 GMT Location: http://www.laia.lt/ Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic CF-RAY: 13f47beac3e50899-FRA Set-Cookie: __cfduid=d9f14e0ba413b6d69fc202834486493f11403566337721; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.laia.lt/ | 200 OK Content-Length: 15866 Content-Type: text/html | clean |
http://www.laia.lt/media/system/js/mootools-core.js.pagespeed.jm.icm_DCUluU.js | 200 OK Content-Length: 95138 Content-Type: application/javascript | clean |
http://www.laia.lt/media/system/js/core.js.pagespeed.jm.AESYeh_Qiv.js | 200 OK Content-Length: 4707 Content-Type: application/javascript | clean |
http://www.laia.lt/media/system/js/caption.js.pagespeed.jm.N0DmbmP4fF.js | 200 OK Content-Length: 657 Content-Type: application/javascript | clean |
http://www.laia.lt/media/system/js/mootools-more.js.pagespeed.jm.SMODr-WPPp.js | 200 OK Content-Length: 234332 Content-Type: application/javascript | clean |
http://laia.lt/plugins/content/attachments/attachments_refresh.js | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=14400 Connection: close Date: Mon, 23 Jun 2014 23:32:20 GMT Location: http://www.laia.lt/plugins/content/attachments/attachments_refresh.js Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Expires: Tue, 24 Jun 2014 03:32:20 GMT Alternate-Protocol: 80:quic CF-Cache-Status: MISS CF-RAY: 13f47bfbc0430899-FRA Set-Cookie: __cfduid=d1d2f8e53f859362dad6df73cf13e12501403566340441; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.laia.lt/plugins/content/attachments/attachments_refresh.js | 200 OK Content-Length: 1835 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/scroll.js | 200 OK Content-Length: 133 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/script.js | 200 OK Content-Length: 11374 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/jquery.js | 200 OK Content-Length: 57344 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/superfish.js | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=14400 Connection: close Date: Mon, 23 Jun 2014 23:32:23 GMT Location: http://www.laia.lt/templates/marhanceblack/js/superfish.js Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Expires: Tue, 24 Jun 2014 03:32:23 GMT Alternate-Protocol: 80:quic CF-Cache-Status: MISS CF-RAY: 13f47c0c74810899-FRA Set-Cookie: __cfduid=d127670a566890f8b0e2400e36742370d1403566343115; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.laia.lt/templates/marhanceblack/js/superfish.js | 200 OK Content-Length: 3835 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/hover.js | 200 OK Content-Length: 4141 Content-Type: application/javascript | clean |
http://laia.lt/templates/marhanceblack/js/slideshow.js | 200 OK Content-Length: 5787 Content-Type: application/javascript | clean |
http://laia.lt/index.php | 200 OK Content-Length: 17138 Content-Type: text/html | clean |
http://laia.lt/media/system/js/mootools-core.js.pagespeed.jm.icm_DCUluU.js | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=14400 Connection: close Date: Mon, 23 Jun 2014 23:32:25 GMT Location: http://www.laia.lt/media/system/js/mootools-core.js.pagespeed.jm.icm_DCUluU.js Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Expires: Tue, 24 Jun 2014 03:32:25 GMT Alternate-Protocol: 80:quic CF-Cache-Status: MISS CF-RAY: 13f47c18965a0899-FRA Set-Cookie: __cfduid=d50ef97fec2ddc9d63a8de72e1f93bfa51403566345054; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.laia.lt/media/system/js/mootools-core.js.pagespeed.jm.icm_dculuu.js | 200 OK Content-Length: 95138 Content-Type: application/javascript | clean |
http://laia.lt/media/system/js/core.js,Mjm.AESYeh_Qiv.js+caption.js,Mjm.N0DmbmP4fF.js.pagespeed.jc.7zewbPqWMS.js | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=14400 Connection: close Date: Mon, 23 Jun 2014 23:32:25 GMT Location: http://www.laia.lt/media/system/js/core.js,Mjm.AESYeh_Qiv.js+caption.js,Mjm.N0DmbmP4fF.js.pagespeed.jc.7zewbPqWMS.js Server: cloudflare-nginx Content-Type: text/html; charset=UTF-8 Expires: Tue, 24 Jun 2014 03:32:25 GMT Alternate-Protocol: 80:quic CF-Cache-Status: MISS CF-RAY: 13f47c1c53950899-FRA Set-Cookie: __cfduid=dfcf0c887cb0a6c7a58b5460db8b9281e1403566345656; expires=Mon, 23-Dec-2019 23:50:00 GMT; path=/; domain=.laia.lt; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.laia.lt/media/system/js/core.js,mjm.aesyeh_qiv.js+caption.js,mjm.n0dmbmp4ff.js.pagespeed.jc.7zewbpqwms.js | 404 Not Found Content-Length: 1806 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=laia.lt
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://laia.lt/
Result: laia.lt is not infected or malware details are not published yet.
Result: laia.lt is not infected or malware details are not published yet.