Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gd.columns.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 23:08:50 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 31381
Content-Type: text/html
...31381 bytes of data.
GET / HTTP/1.1
Host: gd.columns.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 23:08:50 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 31381
Content-Type: text/html
...31381 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gd.columns.com
Referer: http://www.google.com/search?q=gd.columns.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gd.columns.com
Referer: http://www.google.com/search?q=gd.columns.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gd.columns.com/ | 200 OK Content-Length: 31381 Content-Type: text/html | clean |
http://www.columns.com/phplive/js/status_image.php?base_url=http://www.columns.com/phplive&l=columns&x=1&deptid=0& | HTTP/1.1 301 Moved Permanently Cache-Control: private Date: Tue, 20 Jan 2015 23:08:51 GMT Location: http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/phplive&l=columns&x=1&deptid=0& Server: Microsoft-IIS/6.0 Content-Length: 298 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/phplive&l=columns&x=1&deptid=0& | 404 Not Found Content-Length: 44072 Content-Type: text/html | clean |
http://shop.columns.com/scripts/jquery-1.7.2.min.js | 200 OK Content-Length: 94840 Content-Type: application/x-javascript | clean |
http://www.columns.com/scripts/jquery-ui-1.10.3.custom.js | 200 OK Content-Length: 76610 Content-Type: application/x-javascript | clean |
http://www.columns.com/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/json2.js | HTTP/1.1 301 Moved Permanently Cache-Control: private Date: Tue, 20 Jan 2015 23:08:56 GMT Location: http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/json2.js Server: Microsoft-IIS/6.0 Content-Length: 267 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/json2.js | 404 Not Found Content-Length: 44043 Content-Type: text/html | clean |
http://shop.columns.com/scripts/jquery-ui-1.10.3.custom.js | 200 OK Content-Length: 76610 Content-Type: application/x-javascript | clean |
http://www.columns.com/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/json2.js | HTTP/1.1 301 Moved Permanently Cache-Control: private Date: Tue, 20 Jan 2015 23:08:58 GMT Location: http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/json2.js Server: Microsoft-IIS/6.0 Content-Length: 275 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/json2.js | 404 Not Found Content-Length: 44053 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44063 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44073 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44083 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44093 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44103 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44113 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44123 Content-Type: text/html | clean |
http://shop.columns.com/page-not-found.aspx?404;http://www.columns.com:80/phplive/js/status_image.php?base_url=http://www.columns.com/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/scripts/json2.js | 404 Not Found Content-Length: 44133 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gd.columns.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gd.columns.com/
Result: gd.columns.com is not infected or malware details are not published yet.
Result: gd.columns.com is not infected or malware details are not published yet.