Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: carstereosubwoofers.net
Result:
HTTP/1.1 200 OK
Date: Thu, 26 Jun 2014 00:26:14 GMT
Accept-Ranges: bytes
ETag: "4feaf975a1d9ce1:c8ad"
Server: Microsoft-IIS/6.0
Content-Length: 6533
Content-Location: http://carstereosubwoofers.net/default.html
Content-Type: text/html
Last-Modified: Mon, 04 Nov 2013 21:04:33 GMT
X-Powered-By: ASP.NET
...6533 bytes of data.
GET / HTTP/1.1
Host: carstereosubwoofers.net
Result:
HTTP/1.1 200 OK
Date: Thu, 26 Jun 2014 00:26:14 GMT
Accept-Ranges: bytes
ETag: "4feaf975a1d9ce1:c8ad"
Server: Microsoft-IIS/6.0
Content-Length: 6533
Content-Location: http://carstereosubwoofers.net/default.html
Content-Type: text/html
Last-Modified: Mon, 04 Nov 2013 21:04:33 GMT
X-Powered-By: ASP.NET
...6533 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: carstereosubwoofers.net
Referer: http://www.google.com/search?q=carstereosubwoofers.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: carstereosubwoofers.net
Referer: http://www.google.com/search?q=carstereosubwoofers.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://carstereosubwoofers.net/ | HTTP/1.1 200 OK Date: Thu, 26 Jun 2014 00:26:14 GMT Accept-Ranges: bytes ETag: "4feaf975a1d9ce1:c8ad" Server: Microsoft-IIS/6.0 Content-Length: 6533 Content-Location: http://carstereosubwoofers.net/default.html Content-Type: text/html Last-Modified: Mon, 04 Nov 2013 21:04:33 GMT X-Powered-By: ASP.NET | clean |
http://carstereosubwoofers.net/default.html | 200 OK Content-Length: 6533 Content-Type: text/html | clean |
http://carstereosubwoofers.net//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://carstereosubwoofers.net/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://lapi.ebay.com/ws/eBayISAPI.dll?EKServer&ai=nqwu%7C%7Cq%21&bdrcolor=000000&cid=0&eksize=1&encode=UTF-8&endcolor=FF0000&endtime=n&fbgcolor=000000&fntcolor=000000&fs=0&hdrcolor=999999&hdrimage=1&hdrsrch=y&img=y&lnkcolor=ffffff&logo=2&num30&numbid=n&paypal=n&popup=n&prvd=9&query=car+stereo+subwoofer&r0=3&shipcost=n&sid=www.carstereosubwoofers.net&siteid=0&sort=MetaEndSort&sortby=endtime&sortdir <span>...111 symbols skipped</span> | 200 OK Content-Length: 38461 Content-Type: text/html | clean |
http://lapi.ebay.com/ws/\""+href+"\""+(target==null||target=="_self"?"":" | HTTP/1.1 302 Moved Temporarily Date: Thu, 26 Jun 2014 00:26:17 GMT Location: http://pages.ebay.com/messages/page_not_responding.html?eBayErrorEventName=p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28gc%3B237a-2014.06.25.17.26.17.382.MST Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28gc%3B237a-146d590d5a6 | clean |
http://pages.ebay.com/messages/page_not_responding.html?ebayerroreventname=p4p%60gu%60m%2bfslehq%60%3c%3dpi%2bpu%28gc%3b237a-2014.06.25.17.26.17.382.mst | 200 OK Content-Length: 8910 Content-Type: text/html | clean |
http://include.ebaystatic.com/js/v/us/ebaybase.js | 200 OK Content-Length: 70441 Content-Type: application/javascript | clean |
http://include.ebaystatic.com/js/v/us/ebaysup.js | 200 OK Content-Length: 17110 Content-Type: application/javascript | clean |
http://lapi.ebay.com/ws/\"" | HTTP/1.1 302 Moved Temporarily Date: Thu, 26 Jun 2014 00:26:19 GMT Location: http://pages.ebay.com/messages/page_not_responding.html?eBayErrorEventName=p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%287%3E107ee-2014.06.25.17.26.19.448.MST Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%287%3E107ee-146d590ddb8 | clean |
http://pages.ebay.com/messages/page_not_responding.html?ebayerroreventname=p4p%60gu%60m%2bfslehq%60%3c%3dpi%2bpu%287%3e107ee-2014.06.25.17.26.19.448.mst | 200 OK Content-Length: 8910 Content-Type: text/html | clean |
http://pages.ebay.com/coverage/index.html | HTTP/1.1 301 Moved Permanently Date: Thu, 26 Jun 2014 00:26:19 GMT ETag: Location: http://pages.ebay.com/ebay-money-back-guarantee/ Server: Apache-Coyote/1.1 Content-Length: 0 Last-Modified: Wed, 26 Jun 2014 00:12:27 GMT RlogId: p4fug%60fvehq%60%3C%3Dsm%7E0a57d.a47b-146d590e0f7 | clean |
http://pages.ebay.com/ebay-money-back-guarantee/ | 200 OK Content-Length: 31264 Content-Type: text/html | clean |
http://pages.ebay.com/jslibrary/jquery-1.10.2.min.js | 200 OK Content-Length: 93118 Content-Type: application/x-javascript | clean |
http://ir.ebaystatic.com/v4js/z/i5/r32gctn0fu3vjkpge2mjhij3q.js | 200 OK Content-Length: 104294 Content-Type: application/x-javascript | clean |
http://include.ebaystatic.com/js/e879/us/ebaybase_v4_e8793us.js | 200 OK Content-Length: 51599 Content-Type: application/javascript | clean |
http://include.ebaystatic.com/js/e879/us/ebaysup_e8793us.js | 200 OK Content-Length: 17110 Content-Type: application/javascript | clean |
http://ir.ebaystatic.com/header/js/all.min?combo=90&rvr=s48rc6&siteid=0&h=97234 | 200 OK Content-Length: 186270 Content-Type: application/x-javascript | clean |
http://pages.ebay.com/coverage/ | HTTP/1.1 301 Moved Permanently Date: Thu, 26 Jun 2014 00:26:23 GMT Location: http://pages.ebay.com/ebay-money-back-guarantee/ Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4fug%60fvehq%60%3C%3Dpie2a57d.2gc3-146d590f061 X-Cnection: close | clean |
http://pages.ebay.com/help/policies/money-back-guarantee.html | 200 OK Content-Length: 47376 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=carstereosubwoofers.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://carstereosubwoofers.net/
Result: carstereosubwoofers.net is not infected or malware details are not published yet.
Result: carstereosubwoofers.net is not infected or malware details are not published yet.