Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ihmc.edu.hk
Result:
GET / HTTP/1.1
Host: ihmc.edu.hk
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: ihmc.edu.hk
Referer: http://www.google.com/search?q=ihmc.edu.hk
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ihmc.edu.hk
Referer: http://www.google.com/search?q=ihmc.edu.hk
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.ihmc.edu.hk/ | HTTP/1.1 302 Found Cache-Control: private Date: Tue, 30 Sep 2014 22:31:22 GMT Location: /index/customIndex.aspx?nnnid=1 Server: Microsoft-IIS/8.0 Content-Length: 156 Content-Type: text/html; charset=utf-8 Set-Cookie: ASP.NET_SessionId=0nvab445e5moeo55oe51ha55; path=/; HttpOnly Set-Cookie: userLanguage=userEnglish; expires=Tue, 30-Sep-2014 22:51:22 GMT; path=/ X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.ihmc.edu.hk/index/customindex.aspx?nnnid=1 | 200 OK Content-Length: 40514 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js | 200 OK Content-Length: 72174 Content-Type: text/javascript | clean |
http://www.ihmc.edu.hk/WebResource.axd?d=1sGaW8EF0qrPv7Gavj-tDC7rKqG32EPuJYDzxMTGAMdk19NKYfVa4PMSa9tWMwDt8nwFn5SCFYWBa3WeK5C7vYE_nZQ1&t=635383230438708886 | 200 OK Content-Length: 20794 Content-Type: application/x-javascript | clean |
http://www.ihmc.edu.hk/ScriptResource.axd?d=_NIJ50S-ykxxPt9Ze6Ch7S_GrOxggnZ1zwXiwXTHPrpK9QyY6iAVTY0F6GW8uewrLR_dPibV3Gk49yJtpuGWqxQy4Rw8ayT1Wdtps4PycrLuZmFr0&t=ffffffffec54f2zh-CHT.js | 200 OK Content-Length: 30872 Content-Type: application/x-javascript | clean |
http://www.ihmc.edu.hk/ScriptResource.axd?d=GRbPLeRzJrqgBouxojBeLgzyz494LTQ4ZMCY5ZvsNgTNrDPU-0-VjGY6NbvQrSHrlFNFU4sgC_vSCtDAfX_KYILY8PqpuF3APfsQF49nSPuBlsTVKZIM2N_7xud9yU1U4gp6cA2&t=ffffffffec54f2zh-CHT.js | 200 OK Content-Length: 11149 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js | 200 OK Content-Length: 200719 Content-Type: text/javascript | clean |
http://www.ihmc.edu.hk/App_Ecmascript/jQueryScrollBar/jquery.easing.1.3.js | 200 OK Content-Length: 8097 Content-Type: application/javascript | clean |
http://www.ihmc.edu.hk/App_Ecmascript/jQueryScrollBar/jquery.mousewheel.min.js | 200 OK Content-Length: 1392 Content-Type: application/javascript | clean |
http://www.ihmc.edu.hk/App_Ecmascript/jQueryScrollBar/jquery.mCustomScrollbar.js | 200 OK Content-Length: 12841 Content-Type: application/javascript | clean |
http://www.ihmc.edu.hk/customIndex.aspx?nnnid=1 | HTTP/1.1 302 Found Cache-Control: private Date: Tue, 30 Sep 2014 22:31:39 GMT Location: /Error/DefaultError.aspx?aspxerrorpath=/customIndex.aspx Server: Microsoft-IIS/8.0 Content-Length: 183 Content-Type: text/html; charset=utf-8 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET | clean |
http://www.ihmc.edu.hk/error/defaulterror.aspx?aspxerrorpath=/customindex.aspx | 200 OK Content-Length: 2357 Content-Type: text/html | clean |
http://www.ihmc.edu.hk/test404page.js | 404 Not Found Content-Length: 1161 Content-Type: text/html | clean |
http://www.ihmc.edu.hk/../CustomPage/paragraphGroup.aspx?ct=customPage&webPageId=1&pageId=1&nnnid=2 | 403 Forbidden Content-Length: 312 Content-Type: text/html | clean |
http://www.ihmc.edu.hk/../CustomPage/paragraphGroup.aspx?ct=customPage&webPageId=6&pageId=6&nnnid=8 | 403 Forbidden Content-Length: 312 Content-Type: text/html | clean |
http://www.ihmc.edu.hk/../CustomPage/paragraphGroup.aspx?ct=customPage&webPageId=38&pageId=195&nnnid=11 | 403 Forbidden Content-Length: 312 Content-Type: text/html | clean |
http://www.ihmc.edu.hk/../CustomPage/paragraphGroup.aspx?ct=customPage&webPageId=41&pageId=198&nnnid=18 | 403 Forbidden Content-Length: 312 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ihmc.edu.hk
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ihmc.edu.hk/
Result: ihmc.edu.hk is not infected or malware details are not published yet.
Result: ihmc.edu.hk is not infected or malware details are not published yet.