Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: arabesky.livejournal.com
Result:
HTTP/1.1 200 OK
Cache-Control: private, proxy-revalidate
Connection: close
Date: Mon, 21 Dec 2015 09:36:41 GMT
Age: 328
ETag: GgZziCqgPHVgdkOGNT4/LwvU+w
Server: nginx
Vary: Accept-Encoding,ETag,User-Agent
Content-MD5: iCqgPHVgdkOGNT4/LwvU+w
Content-Type: text/html; charset=utf-8
Set-Cookie: ljident=2885948844.20480.0000;domain=.livejournal.com; path=/
X-AWS-Id: ws07
X-Beta: http://varnish
X-Gateway: bil1-swlb04
X-LJ-Flow-ID: VnfG4KwVBEYAADZe3FEAAAAR
X-Varnish: 266834269 266752519
X-VWS-Id: bil1-varn30
GET / HTTP/1.1
Host: arabesky.livejournal.com
Result:
HTTP/1.1 200 OK
Cache-Control: private, proxy-revalidate
Connection: close
Date: Mon, 21 Dec 2015 09:36:41 GMT
Age: 328
ETag: GgZziCqgPHVgdkOGNT4/LwvU+w
Server: nginx
Vary: Accept-Encoding,ETag,User-Agent
Content-MD5: iCqgPHVgdkOGNT4/LwvU+w
Content-Type: text/html; charset=utf-8
Set-Cookie: ljident=2885948844.20480.0000;domain=.livejournal.com; path=/
X-AWS-Id: ws07
X-Beta: http://varnish
X-Gateway: bil1-swlb04
X-LJ-Flow-ID: VnfG4KwVBEYAADZe3FEAAAAR
X-Varnish: 266834269 266752519
X-VWS-Id: bil1-varn30
Second query (visit from search engine):
GET / HTTP/1.1
Host: arabesky.livejournal.com
Referer: http://www.google.com/search?q=arabesky.livejournal.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: arabesky.livejournal.com
Referer: http://www.google.com/search?q=arabesky.livejournal.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://arabesky.livejournal.com/ | 200 OK Content-Length: 300678 Content-Type: text/html | clean |
http://l-stat.livejournal.net/js/??ads/criteo.js,ads/montblanc.js,ads/adfox.custom.js,ads/adfox.asyn.code.ver3.js,ads/adfox.asyn.code.scroll.js?v=1450352580 | 200 OK Content-Length: 36021 Content-Type: application/x-javascript | clean |
http://arabesky.livejournal.com/friends | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 21 Dec 2015 09:36:45 GMT Accept-Ranges: bytes Age: 327 Location: http://arabesky.livejournal.com/friends/ Server: nginx Content-Length: 375 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: ljident=2835617196.20480.0000;domain=.livejournal.com; path=/ X-Beta: http://varnish X-Gateway: bil1-swlb01 X-Varnish: 266835312 266753877 X-VWS-Id: bil1-varn30 | clean |
http://arabesky.livejournal.com/friends/ | HTTP/1.1 302 Found Connection: close Date: Mon, 21 Dec 2015 09:36:45 GMT Accept-Ranges: bytes Age: 327 Location: http://arabesky.livejournal.com/feed Server: nginx Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Set-Cookie: ljident=2986612140.20480.0000;domain=.livejournal.com; path=/ X-AWS-Id: ws26 X-Beta: http://varnish X-Gateway: bil1-swlb10 X-LJ-Flow-ID: VnfG5qwVBFkAAEw@RRwAAAAN X-Varnish: 266835425 266753980 X-VWS-Id: bil1-varn30 | clean |
http://arabesky.livejournal.com/feed | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 21 Dec 2015 09:36:45 GMT Accept-Ranges: bytes Age: 327 Location: http://arabesky.livejournal.com/feed/ Server: nginx Content-Length: 372 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: ljident=2902726060.20480.0000;domain=.livejournal.com; path=/ X-Beta: http://varnish X-Gateway: bil1-swlb05 X-Varnish: 266835530 266754092 X-VWS-Id: bil1-varn30 | clean |
http://arabesky.livejournal.com/feed/ | HTTP/1.1 200 OK Cache-Control: private, proxy-revalidate Connection: close Date: Mon, 21 Dec 2015 09:36:46 GMT Age: 0 ETag: GgZzVZvUv7CTijSM7LtjSS08vQ Server: nginx Vary: Accept-Encoding,ETag Content-MD5: VZvUv7CTijSM7LtjSS08vQ Content-Type: text/html; charset=utf-8 Set-Cookie: prop_friendsfeed_tour=%7B%22rss%22%3A0%7D; expires=Monday, 28-Dec-2015 09:36:46 GMT; path=/; domain=.livejournal.com Set-Cookie: ljident=2953057708.20480.0000;domain=.livejournal.com; path=/ X-AWS-Id: ws04 X-Beta: http://varnish X-End: end: arabesky.livejournal.com/feed/<_c->prop_hide_smartbanner=0; <_cs->N0C00KIE5 X-Gateway: bil1-swlb08 X-LJ-Flow-ID: VnfILqwVBEMAACnRdPIAAAAX X-Varnish: 266835631 X-VWS-Id: bil1-varn30 | clean |
http://arabesky.livejournal.com/feed/?nojs=1 | 200 OK Content-Length: 300616 Content-Type: text/html | clean |
http://l-stat.livejournal.net/js/??.ljlib.js?v=1450352580 | 200 OK Content-Length: 301184 Content-Type: application/x-javascript | clean |
http://l-stat.livejournal.net/js/??scheme/schemius.js,jquery/jquery.lj.repostbutton.js,threeposts.js,friendstimes-scroller.js,jquery/jquery.lj.sidePane.js,jquery/jquery.lj.ljcut.js,feed/feed.v3.js,core/angular/messages.js,ljlive/main.js?v=1450352580 | 200 OK Content-Length: 302632 Content-Type: application/x-javascript | clean |
http://l-stat.livejournal.net/js/lib/xtcore.js | 200 OK Content-Length: 23046 Content-Type: application/x-javascript | clean |
http://arabesky.livejournal.com/
| 200 OK Content-Length: 301828 Content-Type: text/html | clean |
http://arabesky.livejournal.com/calendar | 200 OK Content-Length: 150032 Content-Type: text/html | clean |
http://l-stat.livejournal.net/js/??jquery/jquery.lj.calendar.js,jquery/jquery.mask.js,controlstrip.js,scheme/schemius.js,jquery/jquery.lj.repostbutton.js,threeposts.js,s2.js,esn.js,jquery/jquery.lj.confirmbubble.js,jquery/jquery.lj.ljcut.js,fb-select-image.js,jquery/jquery.lj.inlineCalendar.js,jquery/jquery.calendarEvents.js,apps.js,apps/appcontainer.js,ljlive/main.js,core/angular/messages.js?v=1450352580 | 200 OK Content-Length: 303832 Content-Type: application/x-javascript | clean |
http://arabesky.livejournal.com/profile | 200 OK Content-Length: 150030 Content-Type: text/html | clean |
http://l-stat.livejournal.net/js/??scheme/schemius.js,profile/main.js,profile_new.js,ljlive/main.js,core/angular/messages.js?v=1450352580 | 200 OK Content-Length: 132593 Content-Type: application/x-javascript | clean |
http://arabesky.livejournal.com/tag/ | 200 OK Content-Length: 262064 Content-Type: text/html | clean |
http://arabesky.livejournal.com/data/rss | 200 OK Content-Length: 302241 Content-Type: text/xml | clean |
http://arabesky.livejournal.com/test404page.js | 404 Not Found Content-Length: 10613 Content-Type: text/html | clean |
http://arabesky.livejournal.com/tag/%23%22damascus%20spring%22 | 200 OK Content-Length: 166274 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=arabesky.livejournal.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://arabesky.livejournal.com/
Result: arabesky.livejournal.com is not infected or malware details are not published yet.
Result: arabesky.livejournal.com is not infected or malware details are not published yet.