Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bpa.com.ve
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bpa.com.ve/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bpa.com.ve
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Thu, 21 Aug 2014 18:36:20 GMT
Pragma: no-cache
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Content-Type: text/html; charset=ISO-8859-1
Expires: Tue, 03 Jul 2001 06:00:00 GMT
Last-Modified: Thu, 21 Aug 2014 18:36:20 GMT
Set-Cookie: PHPSESSID=142f82014afa6301b2fd9c98b011628f; path=/
X-Powered-By: PHP/5.3.2
GET / HTTP/1.1
Host: bpa.com.ve
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Thu, 21 Aug 2014 18:36:20 GMT
Pragma: no-cache
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Content-Type: text/html; charset=ISO-8859-1
Expires: Tue, 03 Jul 2001 06:00:00 GMT
Last-Modified: Thu, 21 Aug 2014 18:36:20 GMT
Set-Cookie: PHPSESSID=142f82014afa6301b2fd9c98b011628f; path=/
X-Powered-By: PHP/5.3.2
Second query (visit from search engine):
GET / HTTP/1.1
Host: bpa.com.ve
Referer: http://www.google.com/search?q=bpa.com.ve
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bpa.com.ve
Referer: http://www.google.com/search?q=bpa.com.ve
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://bpa.com.ve/ | 200 OK Content-Length: 14113 Content-Type: text/html | clean |
http://bpa.com.ve/Scripts/AC_RunActiveContent.js | 200 OK Content-Length: 3233 Content-Type: application/javascript | clean |
http://bpa.com.ve/Scripts/AC_ActiveX.js | 200 OK Content-Length: 2057 Content-Type: application/javascript | clean |
http://bpa.com.ve/Scripts/jquery-1.3.2.js | 200 OK Content-Length: 120619 Content-Type: application/javascript | clean |
http://bpa.com.ve/greybox/AJS.js | 200 OK Content-Length: 10396 Content-Type: application/javascript | clean |
http://bpa.com.ve/greybox/AJS_fx.js | 200 OK Content-Length: 3192 Content-Type: application/javascript | clean |
http://bpa.com.ve/greybox/gb_scripts.js | 200 OK Content-Length: 11909 Content-Type: application/javascript | clean |
http://bpa.com.ve/Scripts/custom.js | 200 OK Content-Length: 133 Content-Type: application/javascript | clean |
http://bpa.com.ve/secciones.php?id_m_contenido=45 | 200 OK Content-Length: 14109 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=24 | 200 OK Content-Length: 16041 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=3 | 200 OK Content-Length: 15590 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=40 | 200 OK Content-Length: 15971 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=41 | 200 OK Content-Length: 12532 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=43 | 200 OK Content-Length: 12549 Content-Type: text/html | clean |
http://bpa.com.ve/secciones.php?id_m_secciones=42 | 200 OK Content-Length: 21303 Content-Type: text/html | clean |