Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: earsound668.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 19:17:13 GMT
Accept-Ranges: bytes
Server: nginx/1.0.15
Vary: Accept-Encoding
Content-Length: 2134
Content-Type: text/html
Last-Modified: Wed, 03 Apr 2013 08:21:17 GMT
...2134 bytes of data.
GET / HTTP/1.1
Host: earsound668.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 19:17:13 GMT
Accept-Ranges: bytes
Server: nginx/1.0.15
Vary: Accept-Encoding
Content-Length: 2134
Content-Type: text/html
Last-Modified: Wed, 03 Apr 2013 08:21:17 GMT
...2134 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: earsound668.com
Referer: http://www.google.com/search?q=earsound668.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: earsound668.com
Referer: http://www.google.com/search?q=earsound668.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://earsound668.com/ | 200 OK Content-Length: 2134 Content-Type: text/html | clean |
http://earsound668.com/p.php | 200 OK Content-Length: 21196 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.7.0/jquery.min.js | 200 OK Content-Length: 94020 Content-Type: text/javascript | clean |
http://earsound668.com/p.php?act=phpinfo | 200 OK Content-Length: 51378 Content-Type: text/html | clean |
http://earsound668.com/p.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 | 200 OK Content-Length: 13308 Content-Type: text/html | clean |
http://earsound668.com/test404page.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
http://earsound668.com/p.php?act=Function | 200 OK Content-Length: 106944 Content-Type: text/html | clean |
http://earsound668.com/phpinfo.php | 200 OK Content-Length: 51275 Content-Type: text/html | clean |
http://earsound668.com/phpinfo.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 | 200 OK Content-Length: 13308 Content-Type: text/html | clean |
http://earsound668.com/phpmyadmin/ | 200 OK Content-Length: 8065 Content-Type: text/html | clean |
http://earsound668.com/phpmyadmin/./js/cross_framing_protection.js?ts=1322760055 | 200 OK Content-Length: 331 Content-Type: application/x-javascript | clean |
http://earsound668.com/phpmyadmin/./js/jquery/jquery-1.4.4.js?ts=1322760055 | 200 OK Content-Length: 78268 Content-Type: application/x-javascript | clean |
http://earsound668.com/phpmyadmin/./js/update-location.js?ts=1322760055 | 200 OK Content-Length: 622 Content-Type: application/x-javascript | clean |
http://earsound668.com/phpmyadmin/./js/functions.js?ts=1322760055 | 200 OK Content-Length: 31563 Content-Type: application/x-javascript | clean |
http://earsound668.com/phpmyadmin/./js/jquery/jquery.qtip-1.0.0.min.js?ts=1322760055 | 200 OK Content-Length: 38434 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=earsound668.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://earsound668.com/
Result: earsound668.com is not infected or malware details are not published yet.
Result: earsound668.com is not infected or malware details are not published yet.