Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=down.myapp.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://down.myapp.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: down.myapp.com
Result:
HTTP/1.1 302 Found
Cache-Control: max-age=0
Connection: close
Date: Mon, 16 Jun 2014 07:22:20 GMT
Location: http://203.205.136.144/down.myapp.com/?mkey=539ebdd9e20bb8bb&f=d488&p=0
Server: nws 1.2.15
Content-Length: 22
Expires: Mon, 16 Jun 2014 07:22:20 GMT
X-Extra-Servers: 203.205.136.145;
...22 bytes of data.
GET / HTTP/1.1
Host: down.myapp.com
Result:
HTTP/1.1 302 Found
Cache-Control: max-age=0
Connection: close
Date: Mon, 16 Jun 2014 07:22:20 GMT
Location: http://203.205.136.144/down.myapp.com/?mkey=539ebdd9e20bb8bb&f=d488&p=0
Server: nws 1.2.15
Content-Length: 22
Expires: Mon, 16 Jun 2014 07:22:20 GMT
X-Extra-Servers: 203.205.136.145;
...22 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: down.myapp.com
Referer: http://www.google.com/search?q=down.myapp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: down.myapp.com
Referer: http://www.google.com/search?q=down.myapp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://down.myapp.com/ | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Mon, 16 Jun 2014 07:22:20 GMT Location: http://203.205.136.144/down.myapp.com/?mkey=539ebdd9e20bb8bb&f=d488&p=0 Server: nws 1.2.15 Content-Length: 22 Expires: Mon, 16 Jun 2014 07:22:20 GMT X-Extra-Servers: 203.205.136.145; | clean |
http://203.205.136.144/down.myapp.com/?mkey=539ebdd9e20bb8bb&f=d488&p=0 | HTTP/1.1 302 Found Connection: keep-alive Date: Mon, 16 Jun 2014 07:22:22 GMT Location: http://114.134.85.114:80/?mkey=539ebdd9e20bb8bb&f=d488&p=0 Server: 3Gdown_DK Content-Length: 22 | clean |
http://114.134.85.114:80/?mkey=539ebdd9e20bb8bb&f=d488&p=0 | 403 Forbidden Content-Length: 564 Content-Type: text/html | clean |
http://114.134.85.114:80/test404page.js | 404 Not Found Content-Length: 522 Content-Type: text/html | clean |