Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: edu.kiau.ac.ir
Result:
HTTP/1.1 200 OK
Date: Mon, 23 Feb 2015 15:27:12 GMT
Accept-Ranges: bytes
ETag: "07593f4233d01:0"
Server: Microsoft-IIS/7.5
Content-Length: 16951
Content-Type: text/html
Last-Modified: Sun, 18 Jan 2015 09:41:38 GMT
X-Powered-By: ASP.NET
...16951 bytes of data.
GET / HTTP/1.1
Host: edu.kiau.ac.ir
Result:
HTTP/1.1 200 OK
Date: Mon, 23 Feb 2015 15:27:12 GMT
Accept-Ranges: bytes
ETag: "07593f4233d01:0"
Server: Microsoft-IIS/7.5
Content-Length: 16951
Content-Type: text/html
Last-Modified: Sun, 18 Jan 2015 09:41:38 GMT
X-Powered-By: ASP.NET
...16951 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: edu.kiau.ac.ir
Referer: http://www.google.com/search?q=edu.kiau.ac.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: edu.kiau.ac.ir
Referer: http://www.google.com/search?q=edu.kiau.ac.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://edu.kiau.ac.ir/ | 200 OK Content-Length: 16951 Content-Type: text/html | clean |
http://edu.kiau.ac.ir/login.aspx | 200 OK Content-Length: 88291 Content-Type: text/html | clean |
http://edu.kiau.ac.ir/WebResource.axd?d=7ywcX_TGgro9NVSSnJgL9aA3iygq-vXOASbOCv11hxaSrBrEiPdXAOwnsHKQ-X0VCRG5uGDGoUbG0ghdl7SKu-tgOr--2O9C5-s-EgbssUs1&t=635475160680975818 | 200 OK Content-Length: 21823 Content-Type: application/x-javascript | clean |
http://edu.kiau.ac.ir/WebResource.axd?d=QFwi6RGjLeK2w79nQ-mC08tjIaHA5urfH4RIB8Fg66IfKoULOWv0R1RuM3L2YjTQdMH_4Wz_MAym3U61OC6mD4SxJtkcAeh1j5FkgvGeTYM1&t=635475160680975818 | 200 OK Content-Length: 21603 Content-Type: application/x-javascript | clean |
http://edu.kiau.ac.ir/test404page.js | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=edu.kiau.ac.ir
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://edu.kiau.ac.ir/
Result: edu.kiau.ac.ir is not infected or malware details are not published yet.
Result: edu.kiau.ac.ir is not infected or malware details are not published yet.