Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: airticket.no
Result:
HTTP/1.1 200 OK
Date: Tue, 16 Dec 2014 03:33:57 GMT
Accept-Ranges: bytes
ETag: "958777d4566d01:0"
Server: Microsoft-IIS/7.5
Content-Length: 1410
Content-Type: text/html
Last-Modified: Sat, 22 Nov 2014 13:18:39 GMT
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...1410 bytes of data.
GET / HTTP/1.1
Host: airticket.no
Result:
HTTP/1.1 200 OK
Date: Tue, 16 Dec 2014 03:33:57 GMT
Accept-Ranges: bytes
ETag: "958777d4566d01:0"
Server: Microsoft-IIS/7.5
Content-Length: 1410
Content-Type: text/html
Last-Modified: Sat, 22 Nov 2014 13:18:39 GMT
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...1410 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: airticket.no
Referer: http://www.google.com/search?q=airticket.no
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: airticket.no
Referer: http://www.google.com/search?q=airticket.no
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://airticket.no/ | HTTP/1.1 200 OK Date: Tue, 16 Dec 2014 03:33:57 GMT Accept-Ranges: bytes ETag: "958777d4566d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1410 Content-Type: text/html Last-Modified: Sat, 22 Nov 2014 13:18:39 GMT X-Powered-By: ASP.NET X-Powered-By-Plesk: PleskWin | clean |
http://airticket.no/index.aspx | 200 OK Content-Length: 95941 Content-Type: text/html | clean |
http://airticket.no/js/crossfade.js | 200 OK Content-Length: 5895 Content-Type: application/x-javascript | clean |
http://airticket.no/fly.aspx | 200 OK Content-Length: 71247 Content-Type: text/html | clean |
http://airticket.no/hotell.aspx | 200 OK Content-Length: 63597 Content-Type: text/html | clean |
http://airticket.no/transfers.aspx | 200 OK Content-Length: 63429 Content-Type: text/html | clean |
http://airticket.no/pakketurer.aspx | 200 OK Content-Length: 64577 Content-Type: text/html | clean |
http://www.reisebazaar.no/js/highSlide/highslide-with-gallery.js | 200 OK Content-Length: 76171 Content-Type: application/x-javascript | clean |
http://www.reisebazaar.no/js/highSlide/highSlideCustomInIframe.js | 200 OK Content-Length: 4612 Content-Type: application/x-javascript | clean |
http://airticket.no/registrer.aspx | 200 OK Content-Length: 156019 Content-Type: text/html | clean |
http://airticket.no/js/smooth.pack.js | 200 OK Content-Length: 1024 Content-Type: application/x-javascript | clean |
http://airticket.no/WebResource.axd?d=WcjWTQKaL5ME3M0hMxm46Oq9yg-1v9cNFGScNssB5NOzy8RZd4aEmzbA2o4Mqg8a5faWVt9h3ychUz7HEtmNe4rFKid2fvK_fHKFVGFlSUM1&t=635182236739663180 | 200 OK Content-Length: 21823 Content-Type: application/x-javascript | clean |
http://airticket.no/WebResource.axd?d=cMdANvaELEhkRRRYJkYcwuZ8ABeoac6qlt-4DFGCFZL_99l-C_qsIdswmdYaGrbsYiEjT-BLUVprg5-2ZA8EdinBRv9zIuBoqQJw2mVzk0g1&t=635182236739663180 | 200 OK Content-Length: 21603 Content-Type: application/x-javascript | clean |
http://airticket.no/kontakt.aspx | 200 OK Content-Length: 76093 Content-Type: text/html | clean |
http://airticket.no/agent/campaign_detail.aspx?campaign_id=44 | HTTP/1.1 302 Found Cache-Control: no-store, must-revalidate, private,no-cache Date: Tue, 16 Dec 2014 03:34:09 GMT Pragma: no-cache Location: /login.aspx Server: Microsoft-IIS/7.5 Content-Length: 128 Content-Type: text/html; charset=utf-8 Expires: 0 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET X-Powered-By-Plesk: PleskWin | clean |
http://airticket.no/login.aspx | 200 OK Content-Length: 29930 Content-Type: text/html | clean |
http://airticket.no/WebResource.axd?d=lc2znZ3I2dKZpX-3c2dWzBjnzcTAtEw1AGdUFggcj4zLwK8QUmiT__2ajaZcAqyUoADXVEVq8y1Qe5iFRSVp2guvZFzYpPTXo_aYysvDnmY1&t=635182236739663180 | 200 OK Content-Length: 3005 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=airticket.no
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://airticket.no/
Result: airticket.no is not infected or malware details are not published yet.
Result: airticket.no is not infected or malware details are not published yet.