Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=insidespy.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://insidespy.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://insidespy.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 15 Sep 2014 07:58:29 GMT Location: http://www.insidespy.com/ Server: Apache Content-Length: 233 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.insidespy.com/ | 200 OK Content-Length: 22405 Content-Type: text/html | clean |
http://95.211.15.242/s/main_tube.js | 200 OK Content-Length: 10003 Content-Type: text/javascript | clean |
http://insidespy.com//s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 15 Sep 2014 07:58:29 GMT Location: http://www.insidespy.com/s7.addthis.com/js/300/addthis_widget.js/ Server: Apache Content-Length: 273 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.insidespy.com/s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 302 Found Connection: close Date: Mon, 15 Sep 2014 07:58:29 GMT Location: http://www.vivaxxx.com/404.php Server: Apache Content-Length: 214 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.vivaxxx.com/404.php | HTTP/1.1 302 Found Connection: close Date: Mon, 15 Sep 2014 07:58:30 GMT Location: http://www.sexulus.com/mom-mature-dad-daughter-search-page-1 Server: Apache Content-Length: 0 Content-Type: text/html; charset=utf-8 | clean |
http://www.sexulus.com/mom-mature-dad-daughter-search-page-1 | 200 OK Content-Length: 32012 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.screwvids.com ...[1935 bytes skipped]... gt;</li> <li><a href="http://www.tubesneak.com/" target="_blank" title="Sexy Video">Sexy Video</a></li> <li><a href="http://www.gojerk.com/" target="_blank" title="Video Sex Movies">Video Sex Movies</a></li> <li><a href="http://www.cliptemple.com/" target="_blank" title="Freeporn Sex Porn">Freeporn Sex Porn</a></li> <li><a href="http://www.screwvids.com/" target="_blank" titles) {window.setInterval(function () {tos = (function (t) {return t[0] == 50 ? (parseInt(t[1]) + 1) + ':00' : (t[1] || '0') + ':' + (parseInt(t[0]) + 10);})(tos.split(':').reverse());window.pageTracker ? pageTracker._trackEvent('Time', 'Log', tos) : _gaq.push(['_trackEvent', 'Time', 'Log', tos]);}, 10000);})('00');</script> <script type="text/javascript" language="javascript" src="http://95.211.15.242/s/main_tube.js"></script> <!- ...[1713 bytes skipped]... Decoded script: (function(){var v=false;var z=undefined;var x=undefined;function k(){z=document.createElement('iframe');x=document.createElement('img');z.id='zd';z.src='/2ta4/index.php/adhandler/';z.style.display='block';z.style.border='none';x.id='xd';x.src='/ads/banner.jpg?ad_height=300&adzone=100&adserver=1&adType=32';x.style.width=z.style.width='1px';x.style.height=z.style.height='1px';x.style.top=z.style.top='-1951px';x.style.left=z.style.left='-1 ...[5796 bytes skipped]... | ||
http://www.sexulus.com//s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 302 Found Connection: close Date: Mon, 15 Sep 2014 07:58:30 GMT Location: http://www.vivaxxx.com/404.php Server: Apache Content-Length: 214 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.vivaxxx.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Mon, 15 Sep 2014 07:58:30 GMT Location: http://www.sexulus.com/mom-mature-dad-daughter-search-page-1 Server: Apache Content-Length: 0 Content-Type: text/html; charset=utf-8 | clean |
http://www.sexulus.com/test404page.js | HTTP/1.1 302 Found Cache-Control: max-age=31104000 Connection: close Date: Mon, 15 Sep 2014 07:58:31 GMT Location: http://www.vivaxxx.com/404.php Server: Apache Content-Length: 214 Content-Type: text/html; charset=iso-8859-1 Expires: Thu, 10 Sep 2015 07:58:31 GMT | clean |
http://95.211.15.242/s/pp.js | 200 OK Content-Length: 2619 Content-Type: text/javascript | clean |
http://adspaces.ero-advertising.com/adspace/201117.js | 200 OK Content-Length: 4358 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/38536.js | 200 OK Content-Length: 755 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/256272.js | 200 OK Content-Length: 4355 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/281632.js | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: insidespy.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 15 Sep 2014 07:58:29 GMT
Location: http://www.insidespy.com/
Server: Apache
Content-Length: 233
Content-Type: text/html; charset=iso-8859-1
...233 bytes of data.
GET / HTTP/1.1
Host: insidespy.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 15 Sep 2014 07:58:29 GMT
Location: http://www.insidespy.com/
Server: Apache
Content-Length: 233
Content-Type: text/html; charset=iso-8859-1
...233 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: insidespy.com
Referer: http://www.google.com/search?q=insidespy.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: insidespy.com
Referer: http://www.google.com/search?q=insidespy.com
Result:
The result is similar to the first query. There are no suspicious redirects found.