Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: a-studia.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 27 Aug 2014 10:25:19 GMT
Accept-Ranges: bytes
ETag: "fb3a22-5cb-4ff82c6777fbe"
Server: Apache/2.2.27 (Unix)
Content-Length: 1483
Content-Type: text/html
Last-Modified: Thu, 31 Jul 2014 20:04:07 GMT
...1483 bytes of data.
GET / HTTP/1.1
Host: a-studia.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 27 Aug 2014 10:25:19 GMT
Accept-Ranges: bytes
ETag: "fb3a22-5cb-4ff82c6777fbe"
Server: Apache/2.2.27 (Unix)
Content-Length: 1483
Content-Type: text/html
Last-Modified: Thu, 31 Jul 2014 20:04:07 GMT
...1483 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: a-studia.de
Referer: http://www.google.com/search?q=a-studia.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: a-studia.de
Referer: http://www.google.com/search?q=a-studia.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://a-studia.de/ | HTTP/1.1 200 OK Connection: close Date: Wed, 27 Aug 2014 10:25:19 GMT Accept-Ranges: bytes ETag: "fb3a22-5cb-4ff82c6777fbe" Server: Apache/2.2.27 (Unix) Content-Length: 1483 Content-Type: text/html Last-Modified: Thu, 31 Jul 2014 20:04:07 GMT | clean |
http://www.a-studia.de/index.php | 200 OK Content-Length: 23428 Content-Type: text/html | clean |
http://conteneur-sotkon.fr/esd.php?id=8285232 | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:20 GMT Location: http://www.conteneur-enterre.fr/esd.php?id=8285232 Server: Apache Vary: Accept-Encoding Content-Length: 258 Content-Type: text/html; charset=iso-8859-1 X-Pad: avoid browser bug | clean |
http://www.conteneur-enterre.fr/esd.php?id=8285232 | 404 Not Found Content-Length: 8446 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.4.3/jquery.min.js | 200 OK Content-Length: 77746 Content-Type: text/javascript | clean |
http://conteneur-sotkon.fr/js/jquery.reject.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:21 GMT Location: http://www.conteneur-enterre.fr/js/jquery.reject.min.js Server: Apache Vary: Accept-Encoding Content-Length: 263 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/jquery.reject.min.js | 200 OK Content-Length: 9905 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/js/columnizer.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:22 GMT Location: http://www.conteneur-enterre.fr/js/columnizer.js Server: Apache Vary: Accept-Encoding Content-Length: 256 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/columnizer.js | 200 OK Content-Length: 6148 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/js/jquery.hoverIntent.minified.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:22 GMT Location: http://www.conteneur-enterre.fr/js/jquery.hoverIntent.minified.js Server: Apache Vary: Accept-Encoding Content-Length: 273 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/jquery.hoverintent.minified.js | 404 Not Found Content-Length: 8446 Content-Type: text/html | clean |
http://www.conteneur-enterre.fr/js/jquery.hoverIntent.minified.js | 200 OK Content-Length: 1609 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/js/prettyPhoto3/js/jquery.prettyPhoto.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:23 GMT Location: http://www.conteneur-enterre.fr/js/prettyPhoto3/js/jquery.prettyPhoto.js Server: Apache Vary: Accept-Encoding Content-Length: 280 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/prettyphoto3/js/jquery.prettyphoto.js | 404 Not Found Content-Length: 8446 Content-Type: text/html | clean |
http://www.conteneur-enterre.fr/js/prettyPhoto3/js/jquery.prettyPhoto.js | 200 OK Content-Length: 29747 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/js/jquery.prettyLoader.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:24 GMT Location: http://www.conteneur-enterre.fr/js/jquery.prettyLoader.js Server: Apache Vary: Accept-Encoding Content-Length: 265 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/jquery.prettyloader.js | 404 Not Found Content-Length: 8446 Content-Type: text/html | clean |
http://www.conteneur-enterre.fr/js/jquery.prettyLoader.js | 200 OK Content-Length: 2596 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/js/main.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:25 GMT Location: http://www.conteneur-enterre.fr/js/main.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/js/main.js | 200 OK Content-Length: 6279 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:25 GMT Location: http://www.conteneur-enterre.fr/ Server: Apache Vary: Accept-Encoding Content-Length: 240 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/ | 200 OK Content-Length: 14781 Content-Type: text/html | clean |
http://www.conteneur-enterre.fr/js/jquery-tools-scroller.min.js | 200 OK Content-Length: 5374 Content-Type: application/javascript | clean |
http://conteneur-sotkon.fr/concept | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 10:25:26 GMT Location: http://www.conteneur-enterre.fr/concept Server: Apache Vary: Accept-Encoding Content-Length: 247 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.conteneur-enterre.fr/concept | 200 OK Content-Length: 11740 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=a-studia.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://a-studia.de/
Result: a-studia.de is not infected or malware details are not published yet.
Result: a-studia.de is not infected or malware details are not published yet.