Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: etwinternational.com
Result:
HTTP/1.1 302 Found
Cache-Control: private
Date: Thu, 09 Oct 2014 16:16:53 GMT
Location: http://www.etwinternational.com/
Server: Microsoft-IIS/7.5
Content-Length: 149
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...149 bytes of data.
GET / HTTP/1.1
Host: etwinternational.com
Result:
HTTP/1.1 302 Found
Cache-Control: private
Date: Thu, 09 Oct 2014 16:16:53 GMT
Location: http://www.etwinternational.com/
Server: Microsoft-IIS/7.5
Content-Length: 149
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...149 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: etwinternational.com
Referer: http://www.google.com/search?q=etwinternational.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: etwinternational.com
Referer: http://www.google.com/search?q=etwinternational.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://etwinternational.com/ | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:16:53 GMT Location: http://www.etwinternational.com/ Server: Microsoft-IIS/7.5 Content-Length: 149 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/ | 200 OK Content-Length: 5926 Content-Type: text/html | clean |
http://www.etwinternational.com/js/site.js | 200 OK Content-Length: 3082 Content-Type: application/x-javascript | clean |
http://etwinternational.com/js/dialog1.js | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:16:56 GMT Location: http://www.etwinternational.com/js/dialog1.js Server: Microsoft-IIS/7.5 Content-Length: 162 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/js/dialog1.js | 200 OK Content-Length: 11850 Content-Type: application/x-javascript | clean |
http://jsq.etwun.com:8080/counter.js | 200 OK Content-Length: 437 Content-Type: application/javascript | clean |
http://etwinternational.com/js/dialog.js | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:17:00 GMT Location: http://www.etwinternational.com/js/dialog.js Server: Microsoft-IIS/7.5 Content-Length: 161 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/js/dialog.js | 200 OK Content-Length: 597 Content-Type: application/x-javascript | clean |
http://etwinternational.com/js/jquery-1.8.3.min.js | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:17:00 GMT Location: http://www.etwinternational.com/js/jquery-1.8.3.min.js Server: Microsoft-IIS/7.5 Content-Length: 171 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/js/jquery-1.8.3.min.js | 200 OK Content-Length: 93637 Content-Type: application/x-javascript | clean |
http://etwinternational.com/about.html | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:17:02 GMT Location: http://www.etwinternational.com/about.html Server: Microsoft-IIS/7.5 Content-Length: 159 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/about.html | 200 OK Content-Length: 10360 Content-Type: text/html | clean |
http://www.etwinternational.com/js/jquery.unveil.js | 200 OK Content-Length: 770 Content-Type: application/x-javascript | clean |
http://usa9.etwun.com/chat/2012/chat.2012.js | 200 OK Content-Length: 13033 Content-Type: application/x-javascript | clean |
http://usa9.etwun.com/chat/2012/top.2012.js | 200 OK Content-Length: 27273 Content-Type: application/x-javascript | clean |
http://etwinternational.com/adverting.html | HTTP/1.1 302 Found Cache-Control: private Date: Thu, 09 Oct 2014 16:17:07 GMT Location: http://www.etwinternational.com/adverting.html Server: Microsoft-IIS/7.5 Content-Length: 163 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.etwinternational.com/adverting.html | 200 OK Content-Length: 50419 Content-Type: text/html | clean |
http://www.etwinternational.com/contact.html | 200 OK Content-Length: 4175 Content-Type: text/html | clean |
http://www.etwinternational.com/chat/Sendmessage.js | 200 OK Content-Length: 2085 Content-Type: application/x-javascript | clean |
http://www.etwinternational.com/cloud.html | 200 OK Content-Length: 8437 Content-Type: text/html | clean |
http://www.etwinternational.com/hall.html | 200 OK Content-Length: 22143 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=etwinternational.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://etwinternational.com/
Result: etwinternational.com is not infected or malware details are not published yet.
Result: etwinternational.com is not infected or malware details are not published yet.