Scanned pages/files
Request | Server response | Status |
http://convertmemp3.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 12 Jan 2015 12:05:20 GMT Location: http://www.convertmemp3.com/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev Content-Length: 236 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.convertmemp3.com/ | 200 OK Content-Length: 9033 Content-Type: text/html | clean |
http://www.convertmemp3.com/jquery.js | 200 OK Content-Length: 84360 Content-Type: application/javascript | clean |
http://convertmemp3.com/main.js?upd=1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 12 Jan 2015 12:05:22 GMT Location: http://www.convertmemp3.com/main.js?upd=1 Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev Content-Length: 249 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.convertmemp3.com/main.js?upd=1 | 200 OK Content-Length: 1899 Content-Type: application/javascript | clean |
http://clkrev.com/adServe/banners?tid=CONVERTMEMP3_2799_6&type=footer&size=728x90 | 200 OK Content-Length: 4643 Content-Type: text/javascript | clean |
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 10591 Content-Type: text/javascript | clean |
http://resources.infolinks.com/js/infolinks_main.js | 200 OK Content-Length: 2001 Content-Type: text/javascript | clean |
http://convertmemp3.com/tos/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 12 Jan 2015 12:05:24 GMT Location: http://www.convertmemp3.com/index.php/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev Content-Length: 246 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.convertmemp3.com/index.php/ | 200 OK Content-Length: 8712 Content-Type: text/html | clean |
http://cdn.fastclick.net/js/adcodes/pubcode.min.js?sid=81463&media_type=5&version=1.3&exc=1 | 200 OK Content-Length: 7796 Content-Type: application/x-javascript | clean |
http://convertmemp3.com/tos/1/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 12 Jan 2015 12:05:25 GMT Location: http://www.convertmemp3.com/index.php/1/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev Content-Length: 248 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.convertmemp3.com/index.php/1/ | 200 OK Content-Length: 8896 Content-Type: text/html | clean |
http://www.convertmemp3.com/tos/ | 200 OK Content-Length: 8435 Content-Type: text/html | clean |
http://www.convertmemp3.com/privacy/ | 200 OK Content-Length: 6415 Content-Type: text/html | clean |
http://www.convertmemp3.com/test404page.js | 200 OK Content-Length: 9080 Content-Type: text/html | clean |
http://www.convertmemp3.com/1/ | 200 OK Content-Length: 6095 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var vclk_options = {sid:81463,media_id:2,media_type:2,version:"1.4",pfc:900000}; Antivirus reports:
| ||
http://cdn.fastclick.net/js/adcodes/pubcode.min.js?sid=81463&media_id=2&media_type=2&version=1.4&exc=1&pfc=900000 | 200 OK Content-Length: 7796 Content-Type: application/x-javascript | clean |
http://www.convertmemp3.com/3/ | 200 OK Content-Length: 6162 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var vclk_options = {sid:81463,media_id:2,media_type:2,version:"1.4",pfc:900000}; Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: convertmemp3.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 12 Jan 2015 12:05:20 GMT
Location: http://www.convertmemp3.com/
Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
GET / HTTP/1.1
Host: convertmemp3.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 12 Jan 2015 12:05:20 GMT
Location: http://www.convertmemp3.com/
Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.10-dev
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: convertmemp3.com
Referer: http://www.google.com/search?q=convertmemp3.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: convertmemp3.com
Referer: http://www.google.com/search?q=convertmemp3.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=convertmemp3.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://convertmemp3.com/
Result: convertmemp3.com is not infected or malware details are not published yet.
Result: convertmemp3.com is not infected or malware details are not published yet.