Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: emergencyambulances.com
Result:
HTTP/1.1 200 OK
Date: Fri, 13 Jun 2014 14:57:11 GMT
Accept-Ranges: bytes
ETag: "6dfae8d26ff3cd1:c8a7"
Server: Microsoft-IIS/6.0
Content-Length: 8967
Content-Location: http://emergencyambulances.com/default.html
Content-Type: text/html
Last-Modified: Tue, 15 Jan 2013 22:29:46 GMT
X-Powered-By: ASP.NET
...8967 bytes of data.
GET / HTTP/1.1
Host: emergencyambulances.com
Result:
HTTP/1.1 200 OK
Date: Fri, 13 Jun 2014 14:57:11 GMT
Accept-Ranges: bytes
ETag: "6dfae8d26ff3cd1:c8a7"
Server: Microsoft-IIS/6.0
Content-Length: 8967
Content-Location: http://emergencyambulances.com/default.html
Content-Type: text/html
Last-Modified: Tue, 15 Jan 2013 22:29:46 GMT
X-Powered-By: ASP.NET
...8967 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: emergencyambulances.com
Referer: http://www.google.com/search?q=emergencyambulances.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: emergencyambulances.com
Referer: http://www.google.com/search?q=emergencyambulances.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://emergencyambulances.com/ | HTTP/1.1 200 OK Date: Fri, 13 Jun 2014 14:57:11 GMT Accept-Ranges: bytes ETag: "6dfae8d26ff3cd1:c8a7" Server: Microsoft-IIS/6.0 Content-Length: 8967 Content-Location: http://emergencyambulances.com/default.html Content-Type: text/html Last-Modified: Tue, 15 Jan 2013 22:29:46 GMT X-Powered-By: ASP.NET | clean |
http://emergencyambulances.com/default.html | 200 OK Content-Length: 8967 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19942 Content-Type: text/javascript | clean |
http://lapi.ebay.com/ws/eBayISAPI.dll?EKServer&ai=nqwu%7C%7Cq%21&bdrcolor=ffffcc&cid=0&eksize=1&encode=UTF-8&endcolor=FF0000&endtime=n&fbgcolor=FFFFFF&fntcolor=5d5d5d&fs=0&hdrcolor=FE0000&hdrimage=1&hdrsrch=n&img=y&lnkcolor=2f0901&logo=3&minprice=100&num=15&numbid=n&paypal=n&popup=n&prvd=9&query=Ambulance&r0=3&shipcost=n&sid=http://www.emergencyambulances.com&siteid=0&sort=MetaEndSort&sortby=endti <span>...148 symbols skipped</span> | 200 OK Content-Length: 35924 Content-Type: text/html | clean |
http://lapi.ebay.com/ws/eBayISAPI.dll?EKServer&ai=nqwu%7C%7Cq%21&bdrcolor=ffffcc&cid=0&eksize=1&encode=UTF-8&endcolor=FF0000&endtime=n&fbgcolor=FFFFFF&fntcolor=5d5d5d&fs=0&hdrcolor=FE0000&hdrimage=1&hdrsrch=n&img=y&lnkcolor=2f0901&logo=3&minprice=100&num=15&numbid=n&paypal=n&popup=n&prvd=9&query=Ambulance&r0=3&shipcost=n&sid=http://\""+href+"\""+(target==null||target=="_self"?"":" | 200 OK Content-Length: 35705 Content-Type: text/html | clean |
http://lapi.ebay.com/ws/eBayISAPI.dll?EKServer&ai=nqwu%7C%7Cq%21&bdrcolor=ffffcc&cid=0&eksize=1&encode=UTF-8&endcolor=FF0000&endtime=n&fbgcolor=FFFFFF&fntcolor=5d5d5d&fs=0&hdrcolor=FE0000&hdrimage=1&hdrsrch=n&img=y&lnkcolor=2f0901&logo=3&minprice=100&num=15&numbid=n&paypal=n&popup=n&prvd=9&query=Ambulance&r0=3&shipcost=n&sid=http://\"" | 200 OK Content-Length: 35705 Content-Type: text/html | clean |
http://lapi.ebay.com/test404page.js | HTTP/1.1 302 Moved Temporarily Date: Fri, 13 Jun 2014 14:57:16 GMT Location: http://pages.ebay.com/messages/page_not_responding.html?eBayErrorEventName=p4p%60gu%60m%2Bfslehq%60%3C%3Dsm%2Bpu56*%3A43%3E6cg-2014.06.13.07.57.16.734.MST Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4p%60gu%60m%2Bfslehq%60%3C%3Dsm%2Bpu56*%3A43%3E6cg-14695bb93be | clean |
http://pages.ebay.com/messages/page_not_responding.html?ebayerroreventname=p4p%60gu%60m%2bfslehq%60%3c%3dsm%2bpu56*%3a43%3e6cg-2014.06.13.07.57.16.734.mst | 200 OK Content-Length: 8910 Content-Type: text/html | clean |
http://include.ebaystatic.com/js/v/us/ebaybase.js | 200 OK Content-Length: 70441 Content-Type: application/javascript | clean |
http://include.ebaystatic.com/js/v/us/ebaysup.js | 200 OK Content-Length: 17110 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=emergencyambulances.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://emergencyambulances.com/
Result: emergencyambulances.com is not infected or malware details are not published yet.
Result: emergencyambulances.com is not infected or malware details are not published yet.