Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: croatia-presse.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 22 Aug 2014 04:30:27 GMT
Accept-Ranges: bytes
ETag: "f83a9a55-ae4c-501205ffacaa1"
Server: Apache
Content-Length: 44620
Content-Type: text/html
Last-Modified: Thu, 21 Aug 2014 09:30:44 GMT
...44620 bytes of data.
GET / HTTP/1.1
Host: croatia-presse.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 22 Aug 2014 04:30:27 GMT
Accept-Ranges: bytes
ETag: "f83a9a55-ae4c-501205ffacaa1"
Server: Apache
Content-Length: 44620
Content-Type: text/html
Last-Modified: Thu, 21 Aug 2014 09:30:44 GMT
...44620 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: croatia-presse.de
Referer: http://www.google.com/search?q=croatia-presse.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: croatia-presse.de
Referer: http://www.google.com/search?q=croatia-presse.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://croatia-presse.de/ | 200 OK Content-Length: 44620 Content-Type: text/html | clean |
http://croatia-presse.de/ac_activex.js | 200 OK Content-Length: 2701 Content-Type: application/x-javascript | clean |
http://croatia-presse.de/Hrvatski%20proizvodi%20stigli%20u%20Rewe.html | 200 OK Content-Length: 21799 Content-Type: text/html | clean |
http://croatia-presse.de/o nama.html | 200 OK Content-Length: 13737 Content-Type: text/html | clean |
http://croatia-presse.de/index.html | 200 OK Content-Length: 44620 Content-Type: text/html | clean |
http://croatia-presse.de/Mijo%20Maric%20o%20laznim%20napadima%20na%20Kongres.html | 200 OK Content-Length: 35488 Content-Type: text/html | clean |
http://croatia-presse.de/VIDEO.html | 200 OK Content-Length: 43816 Content-Type: text/html | clean |
http://croatia-presse.de/vid43.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/test404page.js | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid31.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid16.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid15.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid48.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid41.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://croatia-presse.de/vid42.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=croatia-presse.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://croatia-presse.de/
Result: croatia-presse.de is not infected or malware details are not published yet.
Result: croatia-presse.de is not infected or malware details are not published yet.