Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://heli-rc.de/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: heli-rc.de Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 16:41:20 GMT Location: http://pillsnot.ru/ Server: Apache Content-Length: 263 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://heli-rc.de/ | 200 OK Content-Length: 1021 Content-Type: text/html | clean |
http://heli-rc.de/test404page.js | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 16:41:20 GMT Location: http://pillsnot.ru/ Server: Apache Content-Length: 263 Content-Type: text/html; charset=iso-8859-1 | clean |
http://pillsnot.ru/ | 500 Can't connect to pillsnot.ru:80 (Bad hostname) Content-Length: 154 Content-Type: text/plain | clean |
http://pillsnot.ru/test404page.js | 500 Can't connect to pillsnot.ru:80 (Bad hostname) Content-Length: 154 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=heli-rc.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://heli-rc.de/
Result: heli-rc.de is not infected or malware details are not published yet.
Result: heli-rc.de is not infected or malware details are not published yet.