Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aa25.cn
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Date: Thu, 24 Jul 2014 08:56:16 GMT
Pragma: no-cache
Location: http://www.aa25.cn/
Server: Microsoft-IIS/6.0
Content-Length: 137
Content-Type: text/html
...137 bytes of data.
GET / HTTP/1.1
Host: aa25.cn
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Date: Thu, 24 Jul 2014 08:56:16 GMT
Pragma: no-cache
Location: http://www.aa25.cn/
Server: Microsoft-IIS/6.0
Content-Length: 137
Content-Type: text/html
...137 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: aa25.cn
Referer: http://www.google.com/search?q=aa25.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aa25.cn
Referer: http://www.google.com/search?q=aa25.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://aa25.cn/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Date: Thu, 24 Jul 2014 08:56:16 GMT Pragma: no-cache Location: http://www.aa25.cn/ Server: Microsoft-IIS/6.0 Content-Length: 137 Content-Type: text/html | clean |
http://www.aa25.cn/ | 200 OK Content-Length: 50299 Content-Type: text/html | clean |
http://siteapp.baidu.com/static/webappservice/uaredirect.js | 200 OK Content-Length: 819 Content-Type: text/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21245 Content-Type: text/javascript | clean |
http://js.users.51.la/1967272.js | 200 OK Content-Length: 1944 Content-Type: application/x-javascript | clean |
http://aa25.cn/ut2.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Date: Thu, 24 Jul 2014 08:56:26 GMT Pragma: no-cache Location: http://www.aa25.cn/ut2.js Server: Microsoft-IIS/6.0 Content-Length: 149 Content-Type: text/html | clean |
http://www.aa25.cn/ut2.js | 200 OK Content-Length: 10651 Content-Type: application/x-javascript | clean |
http://aa25.cn/index.shtml | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Date: Thu, 24 Jul 2014 08:56:27 GMT Pragma: no-cache Location: http://www.aa25.cn/index.shtml Server: Microsoft-IIS/6.0 Content-Length: 159 Content-Type: text/html | clean |
http://www.aa25.cn/index.shtml | 200 OK Content-Length: 50299 Content-Type: text/html | clean |
http://www.aa25.cn/layout/index.shtml | 200 OK Content-Length: 19068 Content-Type: text/html | clean |
http://www.aa25.cn/v3/js/skin.js | 200 OK Content-Length: 1322 Content-Type: application/x-javascript | clean |
http://www.aa25.cn/div_css/index.shtml | 200 OK Content-Length: 23444 Content-Type: text/html | clean |
http://cpro.baidustatic.com/cpro/ui/c.js | 200 OK Content-Length: 65606 Content-Type: application/x-javascript | clean |
http://www.aa25.cn/css_example/index.shtml | 200 OK Content-Length: 22916 Content-Type: text/html | clean |
http://www.aa25.cn/code/index.shtml | 200 OK Content-Length: 21741 Content-Type: text/html | clean |
http://www.aa25.cn/web_master/index.shtml | 200 OK Content-Length: 22739 Content-Type: text/html | clean |
http://www.aa25.cn/Tech/index.shtml | 200 OK Content-Length: 22254 Content-Type: text/html | clean |
http://www.aa25.cn/download/index.shtml | 200 OK Content-Length: 23590 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aa25.cn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://aa25.cn/
Result: aa25.cn is not infected or malware details are not published yet.
Result: aa25.cn is not infected or malware details are not published yet.