Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 101103.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 07 Mar 2015 12:59:07 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sat, 07 Mar 2015 12:59:07 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 55c0b4ac2ff198575508f3f9de2cbc09=e341b92702efb3cf91591bccd7aa9392; path=/
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: 101103.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 07 Mar 2015 12:59:07 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sat, 07 Mar 2015 12:59:07 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 55c0b4ac2ff198575508f3f9de2cbc09=e341b92702efb3cf91591bccd7aa9392; path=/
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: 101103.net
Referer: http://www.google.com/search?q=101103.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 101103.net
Referer: http://www.google.com/search?q=101103.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://101103.net/ | 200 OK Content-Length: 23948 Content-Type: text/html | clean |
http://101103.net/media/system/js/caption.js | 200 OK Content-Length: 1721 Content-Type: application/javascript | clean |
http://101103.net/index.php?option=com_user&view=reset | 200 OK Content-Length: 7522 Content-Type: text/html | clean |
http://101103.net/media/system/js/validate.js | 200 OK Content-Length: 4246 Content-Type: application/javascript | clean |
http://101103.net/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_user&view=remind | 200 OK Content-Length: 7465 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_user&view=register | 200 OK Content-Length: 8644 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_content&view=article&id=51:2009-10-22-21-32-33&catid=1:latest-news&Itemid=50 | 200 OK Content-Length: 11361 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_content&view=category&layout=blog&id=1&Itemid=50 | 200 OK Content-Length: 15784 Content-Type: text/html | clean |
http://101103.net/index.php?view=article&catid=1%3Alatest-news&id=51%3A2009-10-22-21-32-33&format=pdf&option=com_content&Itemid=50 | 200 OK Content-Length: 161268 Content-Type: application/pdf | clean |
http://101103.net/index.php?view=article&catid=1%3Alatest-news&id=51%3A2009-10-22-21-32-33&tmpl=component&print=1&layout=default&page=&option=com_content&Itemid=50 | 200 OK Content-Length: 4856 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_mailto&tmpl=component&link=aHR0cDovLzEwMTEwMy5uZXQvaW5kZXgucGhwP29wdGlvbj1jb21fY29udGVudCZ2aWV3PWFydGljbGUmaWQ9NTE6MjAwOS0xMC0yMi0yMS0zMi0zMyZjYXRpZD0xOmxhdGVzdC1uZXdzJkl0ZW1pZD01MA== | 200 OK Content-Length: 3087 Content-Type: text/html | clean |
http://101103.net/index.php?view=article&catid=1%3Alatest-news&id=49%3Asodor&format=pdf&option=com_content&Itemid=50 | 200 OK Content-Length: 203592 Content-Type: application/pdf | clean |
http://101103.net/index.php?view=article&catid=1%3Alatest-news&id=49%3Asodor&tmpl=component&print=1&layout=default&page=&option=com_content&Itemid=50 | 200 OK Content-Length: 3790 Content-Type: text/html | clean |
http://101103.net/index.php?option=com_mailto&tmpl=component&link=aHR0cDovLzEwMTEwMy5uZXQvaW5kZXgucGhwP29wdGlvbj1jb21fY29udGVudCZ2aWV3PWFydGljbGUmaWQ9NDk6c29kb3ImY2F0aWQ9MTpsYXRlc3QtbmV3cyZJdGVtaWQ9NTA= | 200 OK Content-Length: 3067 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=101103.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://101103.net/
Result: 101103.net is not infected or malware details are not published yet.
Result: 101103.net is not infected or malware details are not published yet.