Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=giaydantuongdep.edu.vn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://giaydantuongdep.edu.vn/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: giaydantuongdep.edu.vn
Result:
HTTP/1.1 500 Duplicate entry 'afd255db941ddd5579452b9a45abf450' for key 'PRIMARY' SQL=INSERT INTO nct_hitcounter_logs(session_id, user_id, ip, timestart, timelast, counter, browser, timezone, lasturl) VALUES('afd255db941ddd5579452b9a45abf450', '0', '78.158.11.226', '1408701884', '1408701884', '0', 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)', '', '')
Cache-Control: no-cache
Connection: close
Date: Fri, 22 Aug 2014 10:04:44 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d232c2bc2e1a36c9bbef938a4fcb8bab=6dfd66c06e2d7ead2f5f600ac89890f7; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: giaydantuongdep.edu.vn
Result:
HTTP/1.1 500 Duplicate entry 'afd255db941ddd5579452b9a45abf450' for key 'PRIMARY' SQL=INSERT INTO nct_hitcounter_logs(session_id, user_id, ip, timestart, timelast, counter, browser, timezone, lasturl) VALUES('afd255db941ddd5579452b9a45abf450', '0', '78.158.11.226', '1408701884', '1408701884', '0', 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)', '', '')
Cache-Control: no-cache
Connection: close
Date: Fri, 22 Aug 2014 10:04:44 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d232c2bc2e1a36c9bbef938a4fcb8bab=6dfd66c06e2d7ead2f5f600ac89890f7; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: giaydantuongdep.edu.vn
Referer: http://www.google.com/search?q=giaydantuongdep.edu.vn
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: giaydantuongdep.edu.vn
Referer: http://www.google.com/search?q=giaydantuongdep.edu.vn
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://giaydantuongdep.edu.vn/ | 500 Duplicate entry 'afd255db941ddd5579452b9a45abf450' for key 'PRIMARY' SQL=INSERT INTO nct_hitcounter_logs(session_id, user_id, ip, timestart, timelast, counter, browser, timezone, lasturl) VALUES('afd255db941ddd5579452b9a45abf450', '0', '78.158.11.226', '1408701884', '1408701884', '0', 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)', '', '') Content-Length: 4598 Content-Type: text/html | clean |
http://giaydantuongdep.edu.vn/index.php | 200 OK Content-Length: 86465 Content-Type: text/html | clean |
http://giaydantuongdep.edu.vn/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/media/system/js/mootools-more.js | 200 OK Content-Length: 166226 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/plugins/system/sl_scrolltotop/assets/js/skyline_scrolltotop.min.js | 200 OK Content-Length: 1339 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/modules/mod_ice_carousel/assets/script_16.js | 200 OK Content-Length: 15706 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/modules/mod_ice_accordion/assets/script_16.js | 200 OK Content-Length: 1220 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/modules/mod_icemegamenu/assets/js/icemegamenu.js | 200 OK Content-Length: 57078 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/components/com_jshopping/js/jquery/jquery-1.6.2.min.js | 200 OK Content-Length: 91556 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/components/com_jshopping/js/jquery/jquery.media.js | 200 OK Content-Length: 17216 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/components/com_jshopping/js/functions.js | 200 OK Content-Length: 32607 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/components/com_jshopping/js/validateForm.js | 200 OK Content-Length: 9202 Content-Type: application/javascript | clean |
http://giaydantuongdep.edu.vn/templates/it_theshop/js/fix-cols.js | 200 OK Content-Length: 1738 Content-Type: application/javascript | clean |