Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gm811.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gm811.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 27 Jan 2015 00:54:28 GMT
Location: http://www.1942gm.com/
Server: Apache
Vary: Accept-Encoding
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
...230 bytes of data.
GET / HTTP/1.1
Host: gm811.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 27 Jan 2015 00:54:28 GMT
Location: http://www.1942gm.com/
Server: Apache
Vary: Accept-Encoding
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
...230 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gm811.com
Referer: http://www.google.com/search?q=gm811.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gm811.com
Referer: http://www.google.com/search?q=gm811.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gm811.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 27 Jan 2015 00:54:28 GMT Location: http://www.1942gm.com/ Server: Apache Vary: Accept-Encoding Content-Length: 230 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1942gm.com/ | HTTP/1.1 200 OK Date: Tue, 27 Jan 2015 00:54:36 GMT Accept-Ranges: bytes ETag: "1cc1f652a138d01:1ef5" Server: Microsoft-IIS/6.0 Content-Length: 461486 Content-Location: http://www.1942gm.com/index.html Content-Type: text/html Last-Modified: Sun, 25 Jan 2015 13:17:52 GMT X-Died: timeout at scan.pm line 1566. X-Powered-By: ASP.NET | clean |
http://www.1942gm.com/index.html | 200 OK Content-Length: 139760 Content-Type: text/html | clean |
http://www.1942gm.com/iframe/loginjs.php | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.1942gm.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://gm811.com/data/js/acmsd/thea40.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 27 Jan 2015 00:54:50 GMT Location: http://www.1942gm.com/data/js/acmsd/thea40.js Server: Apache Vary: Accept-Encoding Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1942gm.com/data/js/acmsd/thea40.js | 200 OK Content-Length: 151 Content-Type: application/x-javascript | clean |
http://gm811.com/data/js/gg.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 27 Jan 2015 00:54:55 GMT Location: http://www.1942gm.com/data/js/gg.js Server: Apache Vary: Accept-Encoding Content-Length: 243 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1942gm.com/data/js/gg.js | 200 OK Content-Length: 325 Content-Type: application/x-javascript | clean |
http://gm811.com/nq.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 27 Jan 2015 00:54:58 GMT Location: http://www.1942gm.com/nq.js Server: Apache Vary: Accept-Encoding Content-Length: 235 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1942gm.com/nq.js | 200 OK Content-Length: 1206 Content-Type: application/x-javascript | clean |
http://gm811.com/data/js/acmsd/thea23.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 27 Jan 2015 00:55:04 GMT Location: http://www.1942gm.com/data/js/acmsd/thea23.js Server: Apache Vary: Accept-Encoding Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1942gm.com/data/js/acmsd/thea23.js | 200 OK Content-Length: 186 Content-Type: application/x-javascript | clean |