Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: epaper.laprensagrafica.com
Result:
HTTP/1.1 302 Found
Connection: close
Date: Wed, 20 Aug 2014 18:56:27 GMT
Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d
Server: Apache/2.2
Content-Length: 338
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: X-Mapping-ihnbadbn=FBE7A7783220951132A28A925BEEDD58; path=/
...338 bytes of data.
GET / HTTP/1.1
Host: epaper.laprensagrafica.com
Result:
HTTP/1.1 302 Found
Connection: close
Date: Wed, 20 Aug 2014 18:56:27 GMT
Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d
Server: Apache/2.2
Content-Length: 338
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: X-Mapping-ihnbadbn=FBE7A7783220951132A28A925BEEDD58; path=/
...338 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: epaper.laprensagrafica.com
Referer: http://www.google.com/search?q=epaper.laprensagrafica.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: epaper.laprensagrafica.com
Referer: http://www.google.com/search?q=epaper.laprensagrafica.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://epaper.laprensagrafica.com/ | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:27 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=FBE7A7783220951132A28A925BEEDD58; path=/ | clean |
http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bnc,l%5d | 200 OK Content-Length: 7155 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.10.1.min.js | 200 OK Content-Length: 93064 Content-Type: application/x-javascript | clean |
http://epaper.laprensagrafica.com/javascripts/jquery.validationEngine-es.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:29 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=48F4B1B4372DA77B202EB2AB22DDF4B4; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://epaper.laprensagrafica.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:29 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=9BA8F8953A92AA30EAA5E1E4109BA116; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://epaper.laprensagrafica.com/javascripts/jquery.validationEngine.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:51:02 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=159FC8446BFBE6F8B643A3CFB7586B52; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://epaper.laprensagrafica.com/javascripts/jquery-ui-1.8.16.custom.min.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:30 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=9BA8F8953A92AA30EAA5E1E4109BA116; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://epaper.laprensagrafica.com/javascripts/jquery-ui-i18n.min.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:31 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=C8CD0361E165440678B1E3FBFD2F8650; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
http://epaper.laprensagrafica.com/js/libs/modernizr-2.5.2.min.js | HTTP/1.1 302 Found Connection: close Date: Wed, 20 Aug 2014 18:56:31 GMT Location: http://epaper.laprensagrafica.com/login/login.php?target=archivo%5bNC,L%5d Server: Apache/2.2 Content-Length: 338 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: X-Mapping-ihnbadbn=C8CD0361E165440678B1E3FBFD2F8650; path=/ X-Cache-Info: not cacheable; response is 302 without expiry time | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=epaper.laprensagrafica.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://epaper.laprensagrafica.com/
Result: epaper.laprensagrafica.com is not infected or malware details are not published yet.
Result: epaper.laprensagrafica.com is not infected or malware details are not published yet.