Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: brandys-wetterseite.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 03:31:30 GMT
Accept-Ranges: bytes
ETag: "475b467-30d4-4da17acc8cd69"
Server: Apache/2.2.27 (Unix)
Content-Length: 12500
Content-Type: text/html
Last-Modified: Thu, 11 Apr 2013 15:45:24 GMT
X-Pad: avoid browser bug
...12500 bytes of data.
GET / HTTP/1.1
Host: brandys-wetterseite.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 03:31:30 GMT
Accept-Ranges: bytes
ETag: "475b467-30d4-4da17acc8cd69"
Server: Apache/2.2.27 (Unix)
Content-Length: 12500
Content-Type: text/html
Last-Modified: Thu, 11 Apr 2013 15:45:24 GMT
X-Pad: avoid browser bug
...12500 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: brandys-wetterseite.de
Referer: http://www.google.com/search?q=brandys-wetterseite.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: brandys-wetterseite.de
Referer: http://www.google.com/search?q=brandys-wetterseite.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://brandys-wetterseite.de/ | 200 OK Content-Length: 12500 Content-Type: text/html | clean |
http://www.webringseite.de/cgi-bin/counterhost/counter.cgi?id=herbert | HTTP/1.1 302 Found Connection: close Date: Thu, 11 Sep 2014 03:31:30 GMT Location: http://www1.webringseite.de Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.4-14+deb7u10 | clean |
http://www1.webringseite.de/ | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Date: Thu, 11 Sep 2014 03:31:31 GMT Pragma: no-cache Server: Apache Vary: User-Agent,Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Thu, 11 Sep 2014 03:31:31 GMT Set-Cookie: tu=ef73627769317f1bd4d673b35c7719a9; expires=Tue, 31-Dec-2019 23:00:00 GMT; path=/; domain=webringseite.de; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANnylWw2vLY4hUn9w06zQKbhKBfvjFUCsdFlb6TdQhxb9RXWXuI4t31c+o8fYOv/s8q1LGPga3DE1L/tHU4LENMCAwEAAQ==_ob4PgOY8iz48IaZ8KVyurrqlVK/p6FNdAd99YvZKqi1uub6IbZcJEYGJc5hHkQ8uZ+FJH+KjaRdKCFS1NTfpgg== X-Cache: MISS from 630475 X-Powered-By: PHP/5.3.3-7+squeeze19 | clean |
http://www1.webringseite.de//?gtnjs=1/ | 200 OK Content-Length: 18737 Content-Type: text/html | clean |
http://img.sedoparking.com/js/jquery-1.4.2.min.js | 200 OK Content-Length: 52579 Content-Type: application/x-javascript | clean |
http://www.google.com/adsense/domains/caf.js | 200 OK Content-Length: 258 Content-Type: text/javascript | clean |
http://www.webringseite.de/test404page.js | HTTP/1.1 302 Found Connection: close Date: Thu, 11 Sep 2014 03:31:32 GMT Location: http://www1.webringseite.de Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.4-14+deb7u10 | clean |
http://www1.webringseite.de/test404page.js | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Date: Thu, 11 Sep 2014 03:31:33 GMT Pragma: no-cache Server: Apache Vary: User-Agent,Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Thu, 11 Sep 2014 03:31:33 GMT Set-Cookie: tu=1bb0662e93c6238f6ffa561f9ff98066; expires=Tue, 31-Dec-2019 23:00:00 GMT; path=/; domain=webringseite.de; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANnylWw2vLY4hUn9w06zQKbhKBfvjFUCsdFlb6TdQhxb9RXWXuI4t31c+o8fYOv/s8q1LGPga3DE1L/tHU4LENMCAwEAAQ==_2SwMpB4fYkbNtePrp9LW/4k0I7h66YNF8W584ae7LbZZAUvMYsfB21Ye4xojh/eI0lOQducUZQaLFbQqgCotCg== X-Cache: MISS from 621097 X-Powered-By: PHP/5.3.3-7+squeeze19 | clean |
http://www1.webringseite.de/test404page.js/?gtnjs=1 | 200 OK Content-Length: 18737 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=brandys-wetterseite.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://brandys-wetterseite.de/
Result: brandys-wetterseite.de is not infected or malware details are not published yet.
Result: brandys-wetterseite.de is not infected or malware details are not published yet.