Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hug2.biz
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=1
Connection: close
Date: Tue, 07 Apr 2015 05:41:16 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 107746
Content-Type: text/html
Expires: Tue, 07 Apr 2015 05:41:17 GMT
Last-Modified: Tue, 07 Apr 2015 05:13:51 GMT
...107746 bytes of data.
GET / HTTP/1.1
Host: hug2.biz
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=1
Connection: close
Date: Tue, 07 Apr 2015 05:41:16 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 107746
Content-Type: text/html
Expires: Tue, 07 Apr 2015 05:41:17 GMT
Last-Modified: Tue, 07 Apr 2015 05:13:51 GMT
...107746 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: hug2.biz
Referer: http://www.google.com/search?q=hug2.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hug2.biz
Referer: http://www.google.com/search?q=hug2.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://hug2.biz/ | 200 OK Content-Length: 107746 Content-Type: text/html | clean |
http://hug2.biz/js/jquery.js | 200 OK Content-Length: 72174 Content-Type: application/x-javascript | clean |
http://hug2.biz/js/category.js | 200 OK Content-Length: 584 Content-Type: application/x-javascript | clean |
http://hug2.biz/js/lib/jquery/jquery-1.6.4.js | 200 OK Content-Length: 183354 Content-Type: application/x-javascript | clean |
http://hug2.biz/js/jquery.rbanner.js | 200 OK Content-Length: 525 Content-Type: application/x-javascript | clean |
http://hug2.biz/js/sbanner/jquery.sbanner.js | 200 OK Content-Length: 6501 Content-Type: application/x-javascript | clean |
http://spdeliver.i-mobile.co.jp/script/ads.js?20101001 | 200 OK Content-Length: 7236 Content-Type: application/javascript | clean |
http://rranking6.ziyu.net/js/adultdougatubo.js | 200 OK Content-Length: 6207 Content-Type: application/x-javascript | clean |
http://pranking5.ziyu.net/js/tubohug.js | 200 OK Content-Length: 7308 Content-Type: application/x-javascript | clean |
http://rranking6.ziyu.net/rank.php?adultdougatubo | 200 OK Content-Length: 396 Content-Type: application/x-javascript | clean |
http://x8.komusou.jp/ufo/149231400 | 200 OK Content-Length: 6308 Content-Type: application/x-javascript | clean |
http://counter1.fc2.com/counter.php?id=89354656 | 200 Ok Content-Length: 1134 Content-Type: application/x-javascript | clean |
http://hug2.biz/rss.xml | 200 OK Content-Length: 64500 Content-Type: text/xml | clean |
http://hug2.biz/test404page.js | 404 Not Found Content-Length: 2738 Content-Type: text/html | clean |
http://hug2.biz/2015/04/1428334850.html | 200 OK Content-Length: 39240 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hug2.biz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hug2.biz/
Result: hug2.biz is not infected or malware details are not published yet.
Result: hug2.biz is not infected or malware details are not published yet.