Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hellxx.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=60
Connection: close
Date: Mon, 08 Jun 2015 10:46:53 GMT
Location: http://www.hellxx.com/
Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
Expires: Mon, 08 Jun 2015 10:47:53 GMT
...230 bytes of data.
GET / HTTP/1.1
Host: hellxx.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=60
Connection: close
Date: Mon, 08 Jun 2015 10:46:53 GMT
Location: http://www.hellxx.com/
Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
Expires: Mon, 08 Jun 2015 10:47:53 GMT
...230 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: hellxx.com
Referer: http://www.google.com/search?q=hellxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hellxx.com
Referer: http://www.google.com/search?q=hellxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://hellxx.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:46:53 GMT Location: http://www.hellxx.com/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 230 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:47:53 GMT | clean |
http://www.hellxx.com/ | 200 OK Content-Length: 84944 Content-Type: text/html | clean |
http://www.hellxx.com/js/anuncio_1000x100.js?id=13 | 200 OK Content-Length: 260 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/329814.js | 200 OK Content-Length: 1236 Content-Type: application/javascript | clean |
http://hellxx.com/libs/prototype/prototype.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:46:55 GMT Location: http://www.hellxx.com/libs/prototype/prototype.js Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 257 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:47:55 GMT | clean |
http://www.hellxx.com/libs/prototype/prototype.js | 200 OK Content-Length: 139853 Content-Type: application/javascript | clean |
http://hellxx.com/js/functions.js?id=41 | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:46:57 GMT Location: http://www.hellxx.com/js/functions.js?id=41 Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 251 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:47:57 GMT | clean |
http://www.hellxx.com/js/functions.js?id=41 | 200 OK Content-Length: 10379 Content-Type: application/javascript | clean |
http://hellxx.com/js/popunder.js?id=02 | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:46:57 GMT Location: http://www.hellxx.com/js/popunder.js?id=02 Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:47:57 GMT | clean |
http://www.hellxx.com/js/popunder.js?id=02 | 200 OK Content-Length: 4071 Content-Type: application/javascript | clean |
http://service.clicksvenue.com/get_embed.php?sid=115&spid=171&scid=10 | 200 OK Content-Length: 946 Content-Type: application/x-javascript | clean |
http://hellxx.com/libs/scriptaculous/scriptaculous.js?load=effects,slider,builder,dragdrop | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:46:58 GMT Location: http://www.hellxx.com/libs/scriptaculous/scriptaculous.js?load=effects,slider,builder,dragdrop Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:47:58 GMT | clean |
http://www.hellxx.com/libs/scriptaculous/scriptaculous.js?load=effects,slider,builder,dragdrop | 200 OK Content-Length: 2644 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/304295.js | 200 OK Content-Length: 17043 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/292590.js | 200 OK Content-Length: 101406 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/158137.js | 200 OK Content-Length: 2384 Content-Type: application/javascript | clean |
http://hellxx.com//s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=60 Connection: close Date: Mon, 08 Jun 2015 10:47:00 GMT Location: http://www.hellxx.com/s7.addthis.com/js/300/addthis_widget.js/ Server: Apache/2.4.10 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 Content-Length: 270 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 08 Jun 2015 10:48:00 GMT | clean |
http://www.hellxx.com/s7.addthis.com/js/300/addthis_widget.js/ | 404 Not Found Content-Length: 25372 Content-Type: text/html | clean |
http://www.hellxx.com/s7.addthis.com/js/300/addthis_widget.js/libs/prototype/prototype.js | 404 Not Found Content-Length: 25372 Content-Type: text/html | clean |
http://www.hellxx.com/s7.addthis.com/js/300/addthis_widget.js/libs/prototype/libs/prototype/prototype.js | 404 Not Found Content-Length: 25372 Content-Type: text/html | clean |
http://www.hellxx.com/s7.addthis.com/js/300/addthis_widget.js/libs/prototype/libs/prototype/libs/prototype/prototype.js | 404 Not Found Content-Length: 25372 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hellxx.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hellxx.com/
Result: hellxx.com is not infected or malware details are not published yet.
Result: hellxx.com is not infected or malware details are not published yet.