Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=doyban.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://doyban.com/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: doyban.com
Result:
HTTP/1.1 200 OK
Date: Mon, 15 Sep 2014 19:08:30 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Length: 2157
Content-Type: text/html; charset=UTF-8
X-Cnection: close
...2157 bytes of data.
GET / HTTP/1.1
Host: doyban.com
Result:
HTTP/1.1 200 OK
Date: Mon, 15 Sep 2014 19:08:30 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Length: 2157
Content-Type: text/html; charset=UTF-8
X-Cnection: close
...2157 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: doyban.com
Referer: http://www.google.com/search?q=doyban.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: doyban.com
Referer: http://www.google.com/search?q=doyban.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://doyban.com/ | 200 OK Content-Length: 2157 Content-Type: text/html | clean |
http://doyban.com/?fp=F5Qj1Qroc4%2BdscpITU8Xq4%2BGukTgLwIdRCUb%2BRkzEd2ckzGqyQ03VsKoyxuNOQeAlMijFSgcUJo%2FfVIdiU2%2FWw%3D%3D&prvtof=c6pmxOzMJr%2Fq%2Be9hepv2mO4R7mbDjJcZSilNOqb3ewg%3D&poru=zMgOkNQ2obvprqxIqjffrcSb0jhnX7b7sit5Wbrzovfg9aISO2kMq1Tu92slWCZP& | 200 OK Content-Length: 271 Content-Type: text/html | clean |
http://doyban.com/test404page.js | 200 OK Content-Length: 271 Content-Type: text/html | clean |