Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: horosho2012.com
Result:
HTTP/1.1 302 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 25 Jan 2015 21:18:31 GMT
Pragma: no-cache
Location: http://horosho2012.com/1318980578R/
Server: nginx/1.7.9
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: uid=le9TsLZ%2BpLZfK5WzYN3v6WnuZvuDCOE9p2iXVk6JfaX4ZVrqat1eRSGpDWMH6Idi; expires=Sun, 25-Jan-2015 23:18:31 GMT; path=/
Set-Cookie: PHPSESSID=2o39o1ro3ov7q8vgcnhslhpco1; path=/
Set-Cookie: token=1318980578; expires=Sun, 25-Jan-2015 22:23:31 GMT; path=/1318980578R
X-Powered-By: PHP/5.4.36-1~dotdeb.1
...0 bytes of data.
GET / HTTP/1.1
Host: horosho2012.com
Result:
HTTP/1.1 302 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 25 Jan 2015 21:18:31 GMT
Pragma: no-cache
Location: http://horosho2012.com/1318980578R/
Server: nginx/1.7.9
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: uid=le9TsLZ%2BpLZfK5WzYN3v6WnuZvuDCOE9p2iXVk6JfaX4ZVrqat1eRSGpDWMH6Idi; expires=Sun, 25-Jan-2015 23:18:31 GMT; path=/
Set-Cookie: PHPSESSID=2o39o1ro3ov7q8vgcnhslhpco1; path=/
Set-Cookie: token=1318980578; expires=Sun, 25-Jan-2015 22:23:31 GMT; path=/1318980578R
X-Powered-By: PHP/5.4.36-1~dotdeb.1
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: horosho2012.com
Referer: http://www.google.com/search?q=horosho2012.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: horosho2012.com
Referer: http://www.google.com/search?q=horosho2012.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://horosho2012.com/ | HTTP/1.1 302 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:31 GMT Pragma: no-cache Location: http://horosho2012.com/1318980578R/ Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: uid=le9TsLZ%2BpLZfK5WzYN3v6WnuZvuDCOE9p2iXVk6JfaX4ZVrqat1eRSGpDWMH6Idi; expires=Sun, 25-Jan-2015 23:18:31 GMT; path=/ Set-Cookie: PHPSESSID=2o39o1ro3ov7q8vgcnhslhpco1; path=/ Set-Cookie: token=1318980578; expires=Sun, 25-Jan-2015 22:23:31 GMT; path=/1318980578R X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/1318980578r/ | 200 OK Content-Length: 16419 Content-Type: text/html | clean |
http://horosho2012.com/js/less-1.3.3.min.js | 200 OK Content-Length: 58193 Content-Type: application/javascript | clean |
http://horosho2012.com/cancel | 200 OK Content-Length: 14097 Content-Type: text/html | clean |
http://horosho2012.com/games.php | 200 OK Content-Length: 20099 Content-Type: text/html | clean |
http://horosho2012.com/games/13 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:32 GMT Pragma: no-cache Location: ../stp1 Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=1migg6vhmdm09j3p61rg68f7c3; path=/ X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/games/../stp1 | HTTP/1.1 302 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:32 GMT Pragma: no-cache Location: http://horosho2012.com/1318980578A/ Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: uid=le9TsLZ%2BpLZfK5WzYN3v6WnuZvuDCOE9p2iXVk6JfaX4ZVrqat1eRSGpDWMH6Idi; expires=Sun, 25-Jan-2015 23:18:32 GMT; path=/ Set-Cookie: PHPSESSID=n725ikm69ckb6osgtdt58o2876; path=/ Set-Cookie: token=1318980578; expires=Sun, 25-Jan-2015 22:23:32 GMT; path=/1318980578A X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/1318980578a/ | 200 OK Content-Length: 16419 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/cancel | 200 OK Content-Length: 14097 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games.php | 200 OK Content-Length: 20099 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/13 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:33 GMT Pragma: no-cache Location: ../stp1 Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=9ne7esv61kv34hfjj0hego25c4; path=/ X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/1318980578a/games/../stp1 | 200 OK Content-Length: 43095 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../cancel | 200 OK Content-Length: 14097 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games.php | 200 OK Content-Length: 20099 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games/13 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:34 GMT Pragma: no-cache Location: ../stp1 Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=7ls41mr3pr9takaj7aj05ecib5; path=/ X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/1318980578a/games/../games/../stp1 | 200 OK Content-Length: 43095 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games/../cancel | 200 OK Content-Length: 14097 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games/../games.php | 200 OK Content-Length: 20099 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games/../games/13 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 25 Jan 2015 21:18:34 GMT Pragma: no-cache Location: ../stp1 Server: nginx/1.7.9 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=6f83ctmv0klq3o8r4ggs20kec7; path=/ X-Powered-By: PHP/5.4.36-1~dotdeb.1 | clean |
http://horosho2012.com/1318980578a/games/../games/../games/../stp1 | 200 OK Content-Length: 43095 Content-Type: text/html | clean |
http://horosho2012.com/1318980578a/games/../games/../games/../cancel | 200 OK Content-Length: 14097 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=horosho2012.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://horosho2012.com/
Result: horosho2012.com is not infected or malware details are not published yet.
Result: horosho2012.com is not infected or malware details are not published yet.