Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: xn-----6kclibftbdbay5cfjkdidhwm9frl.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 24 Aug 2014 17:34:18 GMT Location: http://www.stlp.4pu.com/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.29 | malicious |
Scanned pages/files
Request | Server response | Status |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/ | 200 OK Content-Length: 6824 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/sample-page/ | 200 OK Content-Length: 8388 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-includes/js/l10n.js?ver=20101110 | 200 OK Content-Length: 308 Content-Type: application/javascript | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-includes/js/comment-reply.js?ver=20090102 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-admin/ | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 24 Aug 2014 17:34:20 GMT Pragma: no-cache Location: http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-login.php?redirect_to=http%3A%2F%2Fxn-----6kclibftbdbay5cfjkdidhwm9frl.com%2Fwp-admin%2F&reauth=1 Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 0 Content-Type: text/html Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Sun, 24 Aug 2014 17:34:20 GMT X-Powered-By: PHP/5.3.29 | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-login.php?redirect_to=http%3a%2f%2fxn-----6kclibftbdbay5cfjkdidhwm9frl.com%2fwp-admin%2f&reauth=1 | 200 OK Content-Length: 2522 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-login.php?action=lostpassword | 200 OK Content-Length: 2141 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/wp-login.php | 200 OK Content-Length: 2522 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/test404page.js | 404 Not Found Content-Length: 6257 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/hello-world/ | 200 OK Content-Length: 10137 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/author/admin/ | 200 OK Content-Length: 7332 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/category/uncategorized/ | 200 OK Content-Length: 7242 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/2011/09/ | 200 OK Content-Length: 6947 Content-Type: text/html | clean |
http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/hello-world/?replytocom=1 | 200 OK Content-Length: 10210 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xn-----6kclibftbdbay5cfjkdidhwm9frl.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xn-----6kclibftbdbay5cfjkdidhwm9frl.com/
Result: xn-----6kclibftbdbay5cfjkdidhwm9frl.com is not infected or malware details are not published yet.
Result: xn-----6kclibftbdbay5cfjkdidhwm9frl.com is not infected or malware details are not published yet.