Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: malwaremustdie.blogspot.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: private, max-age=0
Connection: close
Date: Sun, 06 Apr 2014 10:43:20 GMT
Location: http://blog.malwaremustdie.org/
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Sun, 06 Apr 2014 10:43:20 GMT
Alternate-Protocol: 80:quic
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
GET / HTTP/1.1
Host: malwaremustdie.blogspot.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: private, max-age=0
Connection: close
Date: Sun, 06 Apr 2014 10:43:20 GMT
Location: http://blog.malwaremustdie.org/
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Sun, 06 Apr 2014 10:43:20 GMT
Alternate-Protocol: 80:quic
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Second query (visit from search engine):
GET / HTTP/1.1
Host: malwaremustdie.blogspot.com
Referer: http://www.google.com/search?q=malwaremustdie.blogspot.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: malwaremustdie.blogspot.com
Referer: http://www.google.com/search?q=malwaremustdie.blogspot.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://malwaremustdie.blogspot.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: private, max-age=0 Connection: close Date: Sun, 06 Apr 2014 10:43:20 GMT Location: http://blog.malwaremustdie.org/ Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Sun, 06 Apr 2014 10:43:20 GMT Alternate-Protocol: 80:quic X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://blog.malwaremustdie.org/ | 200 OK Content-Length: 165845 Content-Type: text/html | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shCore.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:22 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shCore.js Server: Apache Vary: Accept-Encoding Content-Length: 246 Content-Type: text/html; charset=iso-8859-1 X-Pad: avoid browser bug | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shcore.js | 200 OK Content-Length: 16175 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushCpp.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:23 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushCpp.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushcpp.js | 200 OK Content-Length: 5284 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushCSharp.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:24 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushCSharp.js Server: Apache Vary: Accept-Encoding Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushcsharp.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushCss.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:25 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushCss.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushcss.js | 200 OK Content-Length: 5694 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushJava.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:27 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushJava.js Server: Apache Vary: Accept-Encoding Content-Length: 251 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushjava.js | 200 OK Content-Length: 2101 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushJScript.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:27 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushJScript.js Server: Apache Vary: Accept-Encoding Content-Length: 254 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushjscript.js | 200 OK Content-Length: 1649 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPhp.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:28 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushPhp.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushphp.js | 200 OK Content-Length: 5246 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPython.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:29 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushPython.js Server: Apache Vary: Accept-Encoding Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushpython.js | 200 OK Content-Length: 2437 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushRuby.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:30 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushRuby.js Server: Apache Vary: Accept-Encoding Content-Length: 251 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushruby.js | 200 OK Content-Length: 2188 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushSql.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:31 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushSql.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushsql.js | 200 OK Content-Length: 3054 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushVb.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:32 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushVb.js Server: Apache Vary: Accept-Encoding Content-Length: 249 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushvb.js | 200 OK Content-Length: 2281 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushXml.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:32 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushXml.js Server: Apache Vary: Accept-Encoding Content-Length: 250 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushxml.js | 200 OK Content-Length: 1998 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPerl.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:33 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushPerl.js Server: Apache Vary: Accept-Encoding Content-Length: 251 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushperl.js | 200 OK Content-Length: 3176 Content-Type: application/x-javascript | clean |
http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPlain.js | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 10:43:34 GMT Location: http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shBrushPlain.js Server: Apache Vary: Accept-Encoding Content-Length: 252 Content-Type: text/html; charset=iso-8859-1 | clean |
http://agorbatchev.typepad.com/pub/sh/3_0_83/scripts/shbrushplain.js | 200 OK Content-Length: 750 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=malwaremustdie.blogspot.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://malwaremustdie.blogspot.com/
Result: malwaremustdie.blogspot.com is not infected or malware details are not published yet.
Result: malwaremustdie.blogspot.com is not infected or malware details are not published yet.