Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gasalarms.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gasalarms.net/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gasalarms.net
Result:
HTTP/1.1 200 OK
Date: Thu, 21 Aug 2014 06:48:24 GMT
Accept-Ranges: bytes
ETag: "9bbd858ad4cd1:dc23"
Server: Microsoft-IIS/6.0
Content-Length: 5437
Content-Location: http://gasalarms.net/default.html
Content-Type: text/html
Last-Modified: Thu, 06 Dec 2012 23:35:16 GMT
X-Powered-By: ASP.NET
...5437 bytes of data.
GET / HTTP/1.1
Host: gasalarms.net
Result:
HTTP/1.1 200 OK
Date: Thu, 21 Aug 2014 06:48:24 GMT
Accept-Ranges: bytes
ETag: "9bbd858ad4cd1:dc23"
Server: Microsoft-IIS/6.0
Content-Length: 5437
Content-Location: http://gasalarms.net/default.html
Content-Type: text/html
Last-Modified: Thu, 06 Dec 2012 23:35:16 GMT
X-Powered-By: ASP.NET
...5437 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gasalarms.net
Referer: http://www.google.com/search?q=gasalarms.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gasalarms.net
Referer: http://www.google.com/search?q=gasalarms.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gasalarms.net/ | HTTP/1.1 200 OK Date: Thu, 21 Aug 2014 06:48:24 GMT Accept-Ranges: bytes ETag: "9bbd858ad4cd1:dc23" Server: Microsoft-IIS/6.0 Content-Length: 5437 Content-Location: http://gasalarms.net/default.html Content-Type: text/html Last-Modified: Thu, 06 Dec 2012 23:35:16 GMT X-Powered-By: ASP.NET | clean |
http://gasalarms.net/default.html | 200 OK Content-Length: 5437 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21183 Content-Type: text/javascript | clean |
http://lapi.ebay.com/ws/eBayISAPI.dll?EKServer&ai=sx%7D%7Dadh%7E%7Dhy%3C%3F%3E&bdrcolor=000000&cid=0&eksize=1&encode=UTF-8&endcolor=FF0000&endtime=n&fbgcolor=FFFFFF&fntcolor=000000&fs=0&hdrcolor=ffffff&hdrimage=1&hdrsrch=n&img=y&lnkcolor=0000FF&logo=3&maxprice=100000&minprice=0&num=12&numbid=n&paypal=n&popup=n&prvd=9&query=Gas+Alarm&r0=3&shipcost=n&sid=gasalarms.net&siteid=0&sort=MetaEndSort&sortb <span>...145 symbols skipped</span> | 200 OK Content-Length: 30772 Content-Type: text/html | clean |
http://lapi.ebay.com/ws/\""+href+"\""+(target==null||target=="_self"?"":" | HTTP/1.1 302 Moved Temporarily Date: Thu, 21 Aug 2014 06:48:26 GMT Location: http://pages.ebay.com/messages/page_not_responding.html?eBayErrorEventName=p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28cabf4d6-2014.08.20.23.48.27.029.MST Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28cabf4d6-147f752d695 | clean |
http://pages.ebay.com/messages/page_not_responding.html?ebayerroreventname=p4p%60gu%60m%2bfslehq%60%3c%3dpi%2bpu%28cabf4d6-2014.08.20.23.48.27.029.mst | 200 OK Content-Length: 8853 Content-Type: text/html | clean |
http://include.ebaystatic.com/js/v/us/ebaybase.js | 200 OK Content-Length: 70479 Content-Type: application/javascript | clean |
http://include.ebaystatic.com/js/v/us/ebaysup.js | 200 OK Content-Length: 17110 Content-Type: application/javascript | clean |
http://lapi.ebay.com/test404page.js | HTTP/1.1 302 Moved Temporarily Date: Thu, 21 Aug 2014 06:48:30 GMT Location: http://pages.ebay.com/messages/page_not_responding.html?eBayErrorEventName=p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28d713c03-2014.08.20.23.48.30.233.MST Server: Apache-Coyote/1.1 Content-Length: 0 RlogId: p4p%60gu%60m%2Bfslehq%60%3C%3Dpi%2Bpu%28d713c03-147f752e319 | clean |
http://pages.ebay.com/messages/page_not_responding.html?ebayerroreventname=p4p%60gu%60m%2bfslehq%60%3c%3dpi%2bpu%28d713c03-2014.08.20.23.48.30.233.mst | 200 OK Content-Length: 8914 Content-Type: text/html | clean |
http://pages.ebay.com/securitycenter/index.html | 200 OK Content-Length: 20753 Content-Type: text/html | clean |
http://ir.ebaystatic.com/v4js/z/i5/r32gctn0fu3vjkpge2mjhij3q.js | 200 OK Content-Length: 104294 Content-Type: application/x-javascript | clean |
http://include.ebaystatic.com/js/e887/us/ebaybase_v4_e8873us.js | 200 OK Content-Length: 51637 Content-Type: application/javascript | clean |
http://include.ebaystatic.com/js/e887/us/ebaysup_e8873us.js | 200 OK Content-Length: 17110 Content-Type: application/javascript | clean |
http://ir.ebaystatic.com/header/js/all.min?combo=90&rvr=s52rc1&siteid=0&h=104235 | 200 OK Content-Length: 186834 Content-Type: application/x-javascript | clean |
http://pages.ebay.com/securitycenter/ | 200 OK Content-Length: 20753 Content-Type: text/html | clean |
http://pages.ebay.com/securitycenter/Index.html | 200 OK Content-Length: 20775 Content-Type: text/html | clean |
http://ir.ebaystatic.com/header/js/all.min?combo=90&rvr=s52rc1&factor=emp&siteid=0&h=104246 | 200 OK Content-Length: 186889 Content-Type: application/x-javascript | clean |