Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ar-vending.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Sep 2014 21:10:35 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 29413
Content-Type: text/html
Last-Modified: Tue, 17 Jun 2014 11:47:27 GMT
...29413 bytes of data.
GET / HTTP/1.1
Host: ar-vending.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Sep 2014 21:10:35 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 29413
Content-Type: text/html
Last-Modified: Tue, 17 Jun 2014 11:47:27 GMT
...29413 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ar-vending.com
Referer: http://www.google.com/search?q=ar-vending.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ar-vending.com
Referer: http://www.google.com/search?q=ar-vending.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ar-vending.com/ | 200 OK Content-Length: 29413 Content-Type: text/html | clean |
http://ar-vending.com/Scripts/AC_RunActiveContent.js | 200 OK Content-Length: 8029 Content-Type: application/javascript | clean |
http://ar-vending.com/encomendar.html | 200 OK Content-Length: 20378 Content-Type: text/html | clean |
http://ar-vending.com/nova_tabela.precos-ctt2013.pdf | 200 OK Content-Length: 18407 Content-Type: application/pdf | clean |
http://ar-vending.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://ar-vending.com/ | 200 OK Content-Length: 29413 Content-Type: text/html | clean |
http://ar-vending.com/localizar-encomenda-via-cttexpresso.html | 200 OK Content-Length: 11286 Content-Type: text/html | clean |
http://ar-vending.com/index.html | 200 OK Content-Length: 29413 Content-Type: text/html | clean |
http://ar-vending.com/contactos.html | 200 OK Content-Length: 13975 Content-Type: text/html | clean |
http://js.sapo.pt/Bundles/Talk2Me.js?mode=1&hash=1a1e5dbdeb14b7e8d39480de2919ebf3d8e860c4&title= Info Aqui. &crc=f6e95f48fccd618ae3a111c0375a3bcade85ec86 | 200 OK Content-Length: 22319 Content-Type: text/javascript | clean |
http://ar-vending.com/login.php | 200 OK Content-Length: 13738 Content-Type: text/html | clean |
http://ar-vending.com/imagens/ctt_exemplo.JPG | 200 OK Content-Length: 68999 Content-Type: image/jpeg | clean |
http://ar-vending.com/index | 404 Not Found Content-Length: 322 Content-Type: text/html | clean |
http://ar-vending.com/Maquinas_nutriva.html | 200 OK Content-Length: 16262 Content-Type: text/html | clean |
http://ar-vending.com/capsulas-lunch.html | 200 OK Content-Length: 14369 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ar-vending.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ar-vending.com/
Result: ar-vending.com is not infected or malware details are not published yet.
Result: ar-vending.com is not infected or malware details are not published yet.