Malicious/Suspicious Redirects
| Request | Server response | Status |
URL: http://zestethik.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: zestethik.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 30 Aug 2013 17:34:34 GMT Location: http://bit.ly/UYIdXL Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.26 | malicious |
URL: http://bit.ly/UYIdXL (imitation of visitor from search engine) GET /UYIdXL HTTP/1.1 Host: bit.ly Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 301 Moved Cache-Control: private; max-age=90 Connection: close Date: Fri, 30 Aug 2013 17:34:49 GMT Location: http://loriannmarchese.com/language/nb-BO/www/0n.php Server: nginx Content-Length: 144 Content-Type: text/html; charset=utf-8 MIME-Version: 1.0 Set-Cookie: _bit=5220d7b9-0016f-00a61-3d1cf10a;domain=.bit.ly;expires=Wed Feb 26 17:34:49 2014;path=/; HttpOnly | malicious |
URL: http://loriannmarchese.com/language/nb-BO/www/0n.php (imitation of visitor from search engine) GET /language/nb-BO/www/0n.php HTTP/1.1 Host: loriannmarchese.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 30 Aug 2013 17:34:49 GMT Location: http://bit.ly/UY3NOX Server: Apache Content-Length: 0 Content-Type: text/html | malicious |
URL: http://bit.ly/a/warning?url=http%3a%2f%2fad%2eadsccco%2ecom%2fad%2ephp%3fuid%3d203&hash=UY3NOX (imitation of visitor from search engine) GET /a/warning?url=http%3a%2f%2fad%2eadsccco%2ecom%2fad%2ephp%3fuid%3d203&hash=UY3NOX HTTP/1.1 Host: bit.ly Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Fri, 30 Aug 2013 17:34:50 GMT Pragma: no-cache Location: https://bitly.com/a/warning?url=http%3a%2f%2fad%2eadsccco%2ecom%2fad%2ephp%3fuid%3d203&hash=UY3NOX Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 | malicious |
Scanned pages/files
| Request | Server response | Status |
http://zestethik.com/ | 200 OK Content-Length: 20441 Content-Type: text/html | clean |
http://zestethik.com/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://zestethik.com/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://zestethik.com/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
http://zestethik.com/media/widgetkit/js/jquery.js | 200 OK Content-Length: 93222 Content-Type: application/javascript | clean |
http://zestethik.com/cache/widgetkit/widgetkit-b8f2fa87.js | 200 OK Content-Length: 47533 Content-Type: application/javascript | clean |
http://zestethik.com/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/multibox/overlay.js | 200 OK Content-Length: 2506 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/multibox/multibox.js | 200 OK Content-Length: 21731 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/multibox/AC_RunActiveContent.js | 200 OK Content-Length: 8029 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/jquery13.js | 200 OK Content-Length: 116878 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/jquery_no_conflict.js | 200 OK Content-Length: 20 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/s5_font_adjuster.js | 200 OK Content-Length: 3800 Content-Type: application/javascript | clean |
http://zestethik.com/templates/photofolio/js/s5_menu_active_and_parent_links.js | 404 Not Found Content-Length: 375 Content-Type: text/html | clean |
http://zestethik.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zestethik.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://zestethik.com/
Result: zestethik.com is not infected or malware details are not published yet.
Result: zestethik.com is not infected or malware details are not published yet.
