Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: disenolamp.com
Result:
HTTP/1.1 200 OK
Date: Thu, 09 Oct 2014 18:14:34 GMT
Accept-Ranges: bytes
ETag: "7454203fc44ccf1:1253"
Server: Microsoft-IIS/6.0
Content-Length: 10296
Content-Location: http://disenolamp.com/index.html
Content-Type: text/html
Last-Modified: Mon, 31 Mar 2014 09:33:17 GMT
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
...10296 bytes of data.
GET / HTTP/1.1
Host: disenolamp.com
Result:
HTTP/1.1 200 OK
Date: Thu, 09 Oct 2014 18:14:34 GMT
Accept-Ranges: bytes
ETag: "7454203fc44ccf1:1253"
Server: Microsoft-IIS/6.0
Content-Length: 10296
Content-Location: http://disenolamp.com/index.html
Content-Type: text/html
Last-Modified: Mon, 31 Mar 2014 09:33:17 GMT
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
...10296 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: disenolamp.com
Referer: http://www.google.com/search?q=disenolamp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: disenolamp.com
Referer: http://www.google.com/search?q=disenolamp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://disenolamp.com/ | HTTP/1.1 200 OK Date: Thu, 09 Oct 2014 18:14:34 GMT Accept-Ranges: bytes ETag: "7454203fc44ccf1:1253" Server: Microsoft-IIS/6.0 Content-Length: 10296 Content-Location: http://disenolamp.com/index.html Content-Type: text/html Last-Modified: Mon, 31 Mar 2014 09:33:17 GMT MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET | clean |
http://disenolamp.com/index.html | 200 OK Content-Length: 10296 Content-Type: text/html | clean |
http://disenolamp.com/js/utilidades.js | 200 OK Content-Length: 10778 Content-Type: application/x-javascript | clean |
http://disenolamp.com/inicio.html | 200 OK Content-Length: 11613 Content-Type: text/html | clean |
http://disenolamp.com/en_desarrollo.html | 200 OK Content-Length: 11139 Content-Type: text/html | clean |
http://disenolamp.com/quienes_somos.html | 200 OK Content-Length: 11914 Content-Type: text/html | clean |
http://disenolamp.com/situacion.html | 200 OK Content-Length: 14813 Content-Type: text/html | clean |
http://maps.google.com/maps?file=api&v=2&sensor=false&key=ABQIAAAA9702xJ2kSd5Mppu_j9RDYBS9vG4eo6Rp9EGYXvhnCejwHBwAihS_PYHj2yAJhxkMHLNtEUYAon6gZg | 200 OK Content-Length: 5096 Content-Type: text/javascript | clean |
http://www.google.com/uds/api?file=uds.js&v=1.0&source=uds-msw&key=ABQIAAAA9702xJ2kSd5Mppu_j9RDYBRMJCHK7lYE5Z5dBhceozhK1WorRRSqqVdwiR-c3t9IxcJquhxDqBgFkA | 200 OK Content-Length: 25393 Content-Type: text/javascript | clean |
http://www.google.com/uds/solutions/mapsearch/gsmapsearch.js?mode=new | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=2592000 Connection: close Date: Thu, 09 Oct 2014 18:08:12 GMT Age: 386 Location: http://uds.googleusercontent.com/uds/solutions/mapsearch/gsmapsearch.js?mode=new Server: sffe Content-Length: 277 Content-Type: text/html; charset=UTF-8 Expires: Sat, 08 Nov 2014 18:08:12 GMT Alternate-Protocol: 80:quic,p=0.002 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://uds.googleusercontent.com/uds/solutions/mapsearch/gsmapsearch.js?mode=new | 200 OK Content-Length: 24484 Content-Type: application/x-javascript | clean |
http://disenolamp.com/contacto.asp | 200 OK Content-Length: 12741 Content-Type: text/html | clean |
http://disenolamp.com/js/formularios.js | 200 OK Content-Length: 20341 Content-Type: application/x-javascript | clean |
http://disenolamp.com/mapa_web.html | 200 OK Content-Length: 19375 Content-Type: text/html | clean |
http://disenolamp.com/producto.html | 200 OK Content-Length: 13268 Content-Type: text/html | clean |
http://disenolamp.com/tridonic.html | 200 OK Content-Length: 14479 Content-Type: text/html | clean |
http://disenolamp.com/descargas_tridonic.html | 200 OK Content-Length: 14533 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=disenolamp.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://disenolamp.com/
Result: disenolamp.com is not infected or malware details are not published yet.
Result: disenolamp.com is not infected or malware details are not published yet.