Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gasxxx.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 07:26:15 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: AVS=6frbblafmlilqp6uvtoqt8aa17; path=/
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: gasxxx.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 07:26:15 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: AVS=6frbblafmlilqp6uvtoqt8aa17; path=/
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: gasxxx.com
Referer: http://www.google.com/search?q=gasxxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gasxxx.com
Referer: http://www.google.com/search?q=gasxxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gasxxx.com/ | 200 OK Content-Length: 81709 Content-Type: text/html | clean |
http://gasxxx.com/templates/frontend/blue/js/jquery-1.2.6.pack.js | 200 OK Content-Length: 31033 Content-Type: application/javascript | clean |
http://gasxxx.com/templates/frontend/blue/js/jquery.livequery.pack.js | 200 OK Content-Length: 2602 Content-Type: application/javascript | clean |
http://gasxxx.com/templates/frontend/blue/js/jquery.rotator-0.2.js | 200 OK Content-Length: 1328 Content-Type: application/javascript | clean |
http://gasxxx.com/templates/frontend/blue/js/jquery.avs-0.2.js | 200 OK Content-Length: 11778 Content-Type: application/javascript | clean |
http://gasxxx.com/templates/frontend/blue/js/jscroller2-1.5.js | 200 OK Content-Length: 5321 Content-Type: application/javascript | clean |
http://syndication.exoclick.com/splash.php?cat=97&idsite=107356&idzone=209716&login=gasxxx&type=3 | 200 OK Content-Length: 5827 Content-Type: application/x-javascript | clean |
http://syndication.exoclick.com/ads.php?type=728x90&login=gasxxx&cat=97&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0?=&text_only=0&show_thumb=&idzone=209707&idsite=107356 | 200 OK Content-Length: 638 Content-Type: text/javascript | clean |
http://adspaces.ero-advertising.com/adspace/139579.js | 200 OK Content-Length: 1447 Content-Type: application/javascript | clean |
http://syndication.exoclick.com/ads.php?type=300x250&login=gasxxx&cat=139&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0?=&text_only=0&show_thumb=&idzone=209752&idsite=107356 | 200 OK Content-Length: 642 Content-Type: text/javascript | clean |
http://syndication.exoclick.com/ads.php?type=160x600&login=gasxxx&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=&text_only=0&show_thumb=&idzone=309796&idsite=107356 | 200 OK Content-Length: 643 Content-Type: text/javascript | clean |
http://adspaces.ero-advertising.com/adspace/136242.js | 200 OK Content-Length: 1442 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/136256.js | 200 OK Content-Length: 2432 Content-Type: application/javascript | clean |
http://syndication.exoclick.com/splash.php?cat=139&idsite=107356&idzone=497603&login=gasxxx&type=4 | 200 OK Content-Length: 4485 Content-Type: text/html | clean |
http://syndication.exoclick.com/test404page.js | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gasxxx.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gasxxx.com/
Result: gasxxx.com is not infected or malware details are not published yet.
Result: gasxxx.com is not infected or malware details are not published yet.