Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gtforce.net.br
Result:
HTTP/1.1 302 Moved Temporarily
Date: Sat, 28 Feb 2015 15:51:18 GMT
Location: http://www.gtforce.net.br
Server: Microsoft-IIS/7.5
Content-Length: 10341
Content-Type: text/html; charset=UTF-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 9898a49c58365f8b2e58223b7f87c9b6=07ee550cec866c9e4f0204b44618c8c9; path=/
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...10341 bytes of data.
GET / HTTP/1.1
Host: gtforce.net.br
Result:
HTTP/1.1 302 Moved Temporarily
Date: Sat, 28 Feb 2015 15:51:18 GMT
Location: http://www.gtforce.net.br
Server: Microsoft-IIS/7.5
Content-Length: 10341
Content-Type: text/html; charset=UTF-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 9898a49c58365f8b2e58223b7f87c9b6=07ee550cec866c9e4f0204b44618c8c9; path=/
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...10341 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gtforce.net.br
Referer: http://www.google.com/search?q=gtforce.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gtforce.net.br
Referer: http://www.google.com/search?q=gtforce.net.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://gtforce.net.br/ | HTTP/1.1 302 Moved Temporarily Date: Sat, 28 Feb 2015 15:51:18 GMT Location: http://www.gtforce.net.br Server: Microsoft-IIS/7.5 Content-Length: 10341 Content-Type: text/html; charset=UTF-8 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 9898a49c58365f8b2e58223b7f87c9b6=07ee550cec866c9e4f0204b44618c8c9; path=/ X-Powered-By: ASP.NET X-Powered-By-Plesk: PleskWin | clean |
http://www.gtforce.net.br/ | 200 OK Content-Length: 35172 Content-Type: text/html | clean |
http://www.gtforce.net.br/media/system/js/modal.js | 200 OK Content-Length: 10588 Content-Type: application/x-javascript | clean |
http://www.gtforce.net.br/components/com_k2/js/k2.js | 200 OK Content-Length: 3077 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 21583 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/plugins/system/rokbox/themes/clean/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/components/com_gantry/js/gantry-totop.js | 200 OK Content-Length: 727 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/components/com_gantry/js/gantry-buildspans.js | 200 OK Content-Length: 722 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/components/com_gantry/js/gantry-inputs.js | 200 OK Content-Length: 2962 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/components/com_gantry/js/gantry-smartload.js | 200 OK Content-Length: 2252 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/templates/2bweb_layout/js/load-transition.js | 200 OK Content-Length: 731 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/modules/mod_roknavmenu/themes/fusion/js/fusion.js | 200 OK Content-Length: 13830 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/modules/mod_rokstories/tmpl/js/rokstories.js | 200 OK Content-Length: 10845 Content-Type: application/x-javascript | clean |
http://gtforce.net.br/index.php | HTTP/1.1 302 Moved Temporarily Date: Sat, 28 Feb 2015 15:51:40 GMT Location: http://www.gtforce.net.br Server: Microsoft-IIS/7.5 Content-Length: 10341 Content-Type: text/html; charset=UTF-8 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 9898a49c58365f8b2e58223b7f87c9b6=9efb38569a5f74633bc00a2868ceb36b; path=/ X-Powered-By: ASP.NET X-Powered-By-Plesk: PleskWin | clean |
http://www.gtforce.net.br/test404page.js | 200 OK Content-Length: 35158 Content-Type: text/html | clean |
http://www.gtforce.net.br/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gtforce.net.br
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gtforce.net.br/
Result: gtforce.net.br is not infected or malware details are not published yet.
Result: gtforce.net.br is not infected or malware details are not published yet.