Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ajithm.hpage.co.in
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 04 Sep 2014 10:02:06 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: PHPSESSID=0fcb0bdee6693be5562a19fac8ac3f3c; path=/
GET / HTTP/1.1
Host: ajithm.hpage.co.in
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 04 Sep 2014 10:02:06 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: PHPSESSID=0fcb0bdee6693be5562a19fac8ac3f3c; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: ajithm.hpage.co.in
Referer: http://www.google.com/search?q=ajithm.hpage.co.in
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ajithm.hpage.co.in
Referer: http://www.google.com/search?q=ajithm.hpage.co.in
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ajithm.hpage.co.in/ | 200 OK Content-Length: 9274 Content-Type: text/html | clean |
http://www.hpage.com/javascript/userpages.js | 200 OK Content-Length: 1166 Content-Type: application/javascript | clean |
http://www.hpage.com/javascript/collection/js_s1.js | 200 OK Content-Length: 3567 Content-Type: application/javascript | clean |
http://www.hpage.com/javascript/collection/js_s2.js | 200 OK Content-Length: 372 Content-Type: application/javascript | clean |
http://www.hpage.com/javascript/collection/js_s4.js | 200 OK Content-Length: 5896 Content-Type: application/javascript | clean |
http://www.hpage.com/javascript/collection/js_s5.js | 200 OK Content-Length: 4390 Content-Type: application/javascript | clean |
http://www.hpage.com/javascript/collection/js_s7.js | 200 OK Content-Length: 205 Content-Type: application/javascript | clean |
http://www.gmodules.com/ig/ifr?url=http://aruljohn.com/gadget/ip.xml&synd=open&w=320&h=150&title=Track+IP+Address%2C+ISP%2C+Country%2C+Proxy&border=%23ffffff%7C3px%2C1px+solid+%23999999&output=js | 200 OK Content-Length: 2533 Content-Type: text/javascript | clean |
http://www.gmodules.com/ig/ifr?url=http://www.believer.com/outreach/versetoday.xml&synd=open&w=320&h=120&title=Bible+Verse+of+the+Day&border=%23ffffff%7C3px%2C1px+solid+%23999999&output=js | 200 OK Content-Length: 2616 Content-Type: text/javascript | clean |
http://www.gmodules.com/ig/ifr?url=http://www.itsfreedownloads.com/ifd_gadget.xml&up_lastTab=New&up_minId=50&up_maxId=100&synd=open&w=320&h=200&title=Free+iTunes+Downloads&border=%23ffffff%7C3px%2C1px+solid+%23999999&output=js | 200 OK Content-Length: 2689 Content-Type: text/javascript | clean |
http://count.asnetworks.de/count.js | 200 OK Content-Length: 994 Content-Type: application/x-javascript | clean |
http://ajithm.hpage.co.in/welcome_57733127.html | 200 OK Content-Length: 9282 Content-Type: text/html | clean |
http://ajithm.hpage.co.in/guestbook.html | 200 OK Content-Length: 21314 Content-Type: text/html | clean |
http://ajithm.hpage.co.in/guestbook_0.html | 200 OK Content-Length: 21753 Content-Type: text/html | clean |
http://ajithm.hpage.co.in/guestbook_10.html | 200 OK Content-Length: 20351 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ajithm.hpage.co.in
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ajithm.hpage.co.in/
Result: ajithm.hpage.co.in is not infected or malware details are not published yet.
Result: ajithm.hpage.co.in is not infected or malware details are not published yet.