Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ban-killer.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ban-killer.com/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ban-killer.com
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sun, 11 Jan 2015 18:45:03 GMT
Location: http://google.com/
Server: nginx/1.4.4
Content-Length: 0
Content-Type: text/html
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
X-Powered-By: PHP/5.2.17
...0 bytes of data.
GET / HTTP/1.1
Host: ban-killer.com
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sun, 11 Jan 2015 18:45:03 GMT
Location: http://google.com/
Server: nginx/1.4.4
Content-Length: 0
Content-Type: text/html
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
X-Powered-By: PHP/5.2.17
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ban-killer.com
Referer: http://www.google.com/search?q=ban-killer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ban-killer.com
Referer: http://www.google.com/search?q=ban-killer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ban-killer.com/ | HTTP/1.1 302 Found Connection: close Date: Sun, 11 Jan 2015 18:45:03 GMT Location: http://google.com/ Server: nginx/1.4.4 Content-Length: 0 Content-Type: text/html P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Powered-By: PHP/5.2.17 | clean |
http://google.com/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sun, 11 Jan 2015 18:45:03 GMT Location: http://www.google.lt/?gws_rd=cr&ei=r8SyVJG0B-flywPCg4GIBQ Server: gws Content-Length: 258 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.02 P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." Set-Cookie: PREF=ID=bee4b8320fc9fdd3:FF=0:TM=1421001903:LM=1421001903:S=h854jWSxKresnZYZ; expires=Tue, 10-Jan-2017 18:45:03 GMT; path=/; domain=.google.com Set-Cookie: NID=67=PgbzNIYfidy6SjLs8OBt1JUyHFUljU_ejKmDQhQbWNcuSMayOy4rXxX96gc8qXMGgYdiQyYUCL9DjDEiKlm7c678OdHUkn-CcWbQ7ZouX8b9SxxbohrCT7wtFu-b-TqY; expires=Mon, 13-Jul-2015 18:45:03 GMT; path=/; domain=.google.com; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/?gws_rd=cr&ei=r8syvjg0b-flywpcg4gibq | 200 OK Content-Length: 51251 Content-Type: text/html | clean |
https://www.google.lt/webhp?tab=ww | 200 OK Content-Length: 64005 Content-Type: text/html | clean |
https://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 57570 Content-Type: text/html | clean |
https://www.google.lt/webhp?hl=lt&tab=iw | 200 OK Content-Length: 64045 Content-Type: text/html | clean |
http://www.google.lt/intl/lt/options/ | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=2592000 Connection: close Date: Fri, 26 Dec 2014 10:38:00 GMT Age: 1411624 Location: http://www.google.lt/intl/lt/about/products/ Server: sffe Content-Length: 241 Content-Type: text/html; charset=UTF-8 Expires: Sun, 25 Jan 2015 10:38:00 GMT Alternate-Protocol: 80:quic,p=0.02 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/intl/lt/about/products/ | 200 OK Content-Length: 7068 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/js/gweb/analytics/autotrack.js/ | 404 Not Found Content-Length: 1471 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt/preferences?hl=lt | 200 OK Content-Length: 64037 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 51270 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=ii | 200 OK Content-Length: 51270 Content-Type: text/html | clean |
http://www.google.lt/history/optout?hl=lt | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sun, 11 Jan 2015 18:45:06 GMT Location: https://history.google.com/history/optout?hl=lt Server: Search-History HTTP Server Content-Length: 244 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.02 Set-Cookie: PREF=ID=eb540cd3f5451f13:TM=1421001906:LM=1421001906:S=CTdYLrS9pgh5bnLZ; expires=Tue, 10-Jan-2017 18:45:06 GMT; path=/; domain=.google.lt X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://history.google.com/history/optout?hl=lt | 200 OK Content-Length: 36865 Content-Type: text/html | clean |
https://history.google.com/history/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sun, 11 Jan 2015 18:45:06 GMT Location: https://accounts.google.com/Login?continue=https://history.google.com/history/&hl=en Server: Search-History HTTP Server Content-Length: 285 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 443:quic,p=0.02 Set-Cookie: PREF=ID=519a740fdec1f2e5:TM=1421001906:LM=1421001906:S=scVfIltc64Ho3bAJ; expires=Tue, 10-Jan-2017 18:45:06 GMT; path=/; domain=.google.com X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/login?continue=https://history.google.com/history/&hl=en | 200 OK Content-Length: 66878 Content-Type: text/html | clean |
https://accounts.google.com/RecoverAccount?continue=https%3A%2F%2Fhistory.google.com%2Fhistory%2F | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Sun, 11 Jan 2015 18:45:07 GMT Location: https://www.google.com/accounts/recovery?hl=en&ard=AHwGkRlWLEzVUfh0l5Cbo3UqTnkHy4WPAj16lI2Lk96suNnOskoV4HDPGLZEBM5KBVASJH0v4xDOZcOL50NBrB7jlrVZE4tpB8hBa1-YURZUvKT8l-koDX6_jd4adtbUxfygtppb2rNnqkJMzv-pdBVMBPcyI4uM9w Server: GSE Content-Length: 399 Content-Type: text/html; charset=UTF-8 Expires: Sun, 11 Jan 2015 18:45:07 GMT Alternate-Protocol: 443:quic,p=0.02 Set-Cookie: GAPS=1:9WI1Uapsl0vzLUGPvh_Hh0pqXsVFoQ:Oj3csZug2ndB78KG;Path=/;Expires=Tue, 10-Jan-2017 18:45:07 GMT;Secure;HttpOnly;Priority=HIGH Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/recovery?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Sun, 11 Jan 2015 18:45:07 GMT Pragma: no-cache Accept-Ranges: none Location: https://www.google.com/accounts/recovery/?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w Server: GSE Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 443:quic,p=0.02 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/recovery/?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Sun, 11 Jan 2015 18:45:07 GMT Pragma: no-cache Accept-Ranges: none Location: https://www.google.com/accounts/RecoverAccount?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w&arr=AHwGkRk-whLP7Pezqhvqneo1RkcmMwBZQySJsSmjhKIAOVI9LRVnvUP3uH2BAgg8jR5DDBn-xH-VN0oygj5k6l02vrvWwUx5KmpNOCWcpD3JkW474kcc3aP_fyoxXhF_1359xU5SHO0z Server: GSE Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 443:quic,p=0.02 Set-Cookie: accountrecoverylocale=en; Expires=Sun, 18-Jan-2015 18:45:07 GMT; Path=/accounts/recovery; Secure; HttpOnly Set-Cookie: S=account-recovery=HC5AQDjLkbw; Domain=.google.com; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/recoveraccount?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w&arr=ahwgkrk-whlp7pezqhvqneo1rkcmmwbzqysjssmjhkiaovi9lrvnvup3uh2bagg8jr5ddbn-xh-vn0oygj5k6l02vrvwwux5kmpnocwcpd3jkw474kcc3ap_fyoxxhf_1359xu5sho0z | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Sun, 11 Jan 2015 18:45:08 GMT Location: https://accounts.google.com/recoveraccount?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w&arr=ahwgkrk-whlp7pezqhvqneo1rkcmmwbzqysjssmjhkiaovi9lrvnvup3uh2bagg8jr5ddbn-xh-vn0oygj5k6l02vrvwwux5kmpnocwcpd3jkw474kcc3ap_fyoxxhf_1359xu5sho0z Server: GSE Content-Length: 550 Content-Type: text/html; charset=UTF-8 Expires: Sun, 11 Jan 2015 18:45:08 GMT Alternate-Protocol: 443:quic,p=0.02 Set-Cookie: GoogleAccountsLocale_session=en; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/recoveraccount?hl=en&ard=ahwgkrlwlezvufh0l5cbo3uqtnkhy4wpaj16li2lk96sunnoskov4hdpglzebm5kbvasjh0v4xdozcol50nbrb7jlrvze4tpb8hba1-yurzuvkt8l-kodx6_jd4adtbuxfygtppb2rnnqkjmzv-pdbvmbpcyi4um9w&arr=ahwgkrk-whlp7pezqhvqneo1rkcmmwbzqysjssmjhkiaovi9lrvnvup3uh2bagg8jr5ddbn-xh-vn0oygj5k6l02vrvwwux5kmpnocwcpd3jkw474kcc3ap_fyoxxhf_1359xu5sho0z | 400 Bad Request Content-Length: 145 Content-Type: text/html | clean |
http://www.google.lt/chrome/index.html?hl=lt&brand=CHNG&utm_source=lt-hpp&utm_medium=hpp&utm_campaign=lt | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sun, 11 Jan 2015 18:45:08 GMT Location: https://www.google.lt/chrome/browser/?hl=lt&brand=CHNG&utm_source=lt-hpp&utm_medium=hpp&utm_campaign=lt Server: sffe Content-Length: 316 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.02 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/chrome/browser/?hl=lt&brand=chng&utm_source=lt-hpp&utm_medium=hpp&utm_campaign=lt | HTTP/1.1 200 OK Cache-Control: private, max-age=0 Connection: close Date: Sun, 11 Jan 2015 18:45:08 GMT Accept-Ranges: none Server: sffe Vary: Accept-Encoding Content-Type: text/html Expires: Sun, 11 Jan 2015 18:45:08 GMT Last-Modified: Tue, 02 Dec 2014 18:04:39 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/chrome/browser/../../chrome/browser/desktop/index.html | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sun, 11 Jan 2015 18:45:08 GMT Location: https://www.google.lt/chrome/browser/desktop/index.html Server: GFE/2.0 Content-Length: 252 Content-Type: text/html; charset=UTF-8 | clean |
https://www.google.lt/chrome/browser/desktop/index.html | 200 OK Content-Length: 43032 Content-Type: text/html | clean |