Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: rinis-automotive.com
Result:
HTTP/1.1 403 Forbidden
Connection: close
Date: Fri, 09 Jan 2015 08:23:29 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 4954
Content-Type: text/html
X-Powered-By: PleskLin
...4954 bytes of data.
GET / HTTP/1.1
Host: rinis-automotive.com
Result:
HTTP/1.1 403 Forbidden
Connection: close
Date: Fri, 09 Jan 2015 08:23:29 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 4954
Content-Type: text/html
X-Powered-By: PleskLin
...4954 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: rinis-automotive.com
Referer: http://www.google.com/search?q=rinis-automotive.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: rinis-automotive.com
Referer: http://www.google.com/search?q=rinis-automotive.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
| Request | Server response | Status |
http://www.gry-on-line.com.pl/ | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:26 GMT Location: http://endow.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://endow.pl/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 18 Jan 2015 03:35:27 GMT Location: http://nedds.pl/ Server: Apache Content-Length: 224 Content-Type: text/html; charset=iso-8859-1 | malicious |
http://nedds.pl/ | 200 OK Content-Length: 108461 Content-Type: text/html | clean |
http://nedds.pl/public/min/index.php?ipbv=1872367b1a891b7b529e8913dfbc345a&g=js | 200 OK Content-Length: 193732 Content-Type: application/x-javascript | clean |
http://nedds.pl/public/min/index.php?ipbv=1872367b1a891b7b529e8913dfbc345a&charset=UTF-8&f=public/js/ipb.js,cache/lang_cache/2/ipb.lang.js,public/js/ips.hovercard.js,public/js/ips.quickpm.js,public/js/ips.board.js | 200 OK Content-Length: 130794 Content-Type: application/x-javascript | clean |
http://www.gry-on-line.com.pl/index.php | 404 Not Found Content-Length: 25 Content-Type: text/html | clean |
http://www.gry-on-line.com.pl/test404page.js | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:31 GMT Location: http://www.gry-on-line.com.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/members/ | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:31 GMT Location: http://www.gry-on-line.com.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/shoutbox/ | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:31 GMT Location: http://www.gry-on-line.com.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/generator/ | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:31 GMT Location: http://www.gry-on-line.com.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/index.php?app=core&module=search&do=viewNewContent&search_app=forums | 404 Not Found Content-Length: 25 Content-Type: text/html | clean |
http://www.gry-on-line.com.pl/topic/1-regulamin-forum-neddspl/ | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:32 GMT Location: http://www.gry-on-line.com.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/?k=880ea6a14ea49e853634fbdc5015a024&setlanguage=1&cal_id=&langid=1 | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:32 GMT Location: http://endow.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/?k=880ea6a14ea49e853634fbdc5015a024&setlanguage=1&cal_id=&langid=2 | HTTP/1.1 301 Moved Permamently Connection: close Date: Sun, 18 Jan 2015 03:35:32 GMT Location: http://endow.pl Server: nginx/1.3.4 Content-Type: text/html X-Frame-Options: SAMEORIGIN | clean |
http://www.gry-on-line.com.pl/index.php?app=core&module=global§ion=register | 404 Not Found Content-Length: 25 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gry-on-line.com.pl
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gry-on-line.com.pl/
Result: gry-on-line.com.pl is not infected or malware details are not published yet.
Result: gry-on-line.com.pl is not infected or malware details are not published yet.
