Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ipm.ac.ir
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ipm.ac.ir/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ipm.ac.ir/ | 200 OK Content-Length: 40605 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: scs.ipm.ac.ir <HTML> <style media="all" type="text/css"> /*<![CDATA[*/ @import url("css/screen1.css"); /*]]>*/ </style> <body> <div id="bgcontentgrad"> <!--?xml version="1.0" encoding="UTF-8"?--> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" ...[4819 bytes skipped]... | ||
http://ipm.ac.ir/files/ip-utilities.js | 200 OK Content-Length: 41522 Content-Type: application/javascript | clean |
http://ipm.ac.ir/files/jquery.js | 200 OK Content-Length: 93868 Content-Type: application/javascript | clean |
http://ipm.ac.ir/js/jquery.js | 200 OK Content-Length: 94840 Content-Type: application/javascript | clean |
http://ipm.ac.ir/js/homepage-async.js | 200 OK Content-Length: 2723 Content-Type: application/javascript | clean |
http://ipm.ac.ir/doc/AnnualReport.pdf | 200 OK Content-Length: 300876 Content-Type: application/pdf | clean |
http://ipm.ac.ir/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://ipm.ac.ir/ipmic.jsp | 200 OK Content-Length: 23480 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: scs.ipm.ac.ir <html>
<head> <!--?xml version="1.0" encoding="UTF-8"?--> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head> <meta name="keywords" content="IPM,Institute for Research in Fundamental Sciences" > <meta content="text/html; charset=UTF-8" http-equiv=" ...[4961 bytes skipped]... | ||
http://ipm.ac.ir/visitors.jsp | 200 OK Content-Length: 34469 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: scs.ipm.ac.ir <html>
<head> <!--?xml version="1.0" encoding="UTF-8"?--> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head> <meta name="keywords" content="IPM,Institute for Research in Fundamental Sciences" > <meta content="text/html; charset=UTF-8" http-equiv=" ...[4961 bytes skipped]... | ||
http://ipm.ac.ir/contact.jsp | 200 OK Content-Length: 26050 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: scs.ipm.ac.ir <html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office">
<head> <!--?xml version="1.0" encoding="UTF-8"?--> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head> <meta name="keywords" content="IPM,Institute for Research i ...[4910 bytes skipped]... | ||
http://ipm.ac.ir/ecatalog/ | 200 OK Content-Length: 2721 Content-Type: text/html | clean |
http://ipm.ac.ir/fa/phonelist.jsp | 200 OK Content-Length: 46890 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: math.ipm.ac.ir ...[2324 bytes skipped]... : 'IPMnassim-regular'; k explorePortlet"> <ul><li class="footerTitle"><span> <div class="bold-tittle"> Ù¾ÚÙÙØ´ÙدÙâÙا</div> </span></li> <li><ul> <li><a href="http://particles.ipm.ir/" target="_blank">ذرات ٠شتابگرÙا</a></li> <li><a href="http://math.ipm.ac.ir/" target="_blank">رÛاضÛات</a></li> <li><a href="http://scs.ipm.ac.ir/" target="_blank">عÙÙÙ Ø´ÙاختÛ</a></li> <li><a href="http://cs.ipm.ac.ir/" target="_blank">عÙÙ٠کا٠پÛÙتر</a></li> <li><a href="http://nano.ipm.ac.ir/" target="_blank">عÙÙÙ ÙاÙÙ</a></li> <li><a href="http://philosophy.ipm.ac.ir/" targ ...[1829 bytes skipped]... | ||
http://ipm.ac.ir/fa/files/ip-utilities.js | 200 OK Content-Length: 41522 Content-Type: application/javascript | clean |
http://ipm.ac.ir/fa/files/jquery.js | 200 OK Content-Length: 93868 Content-Type: application/javascript | clean |
http://ipm.ac.ir/fa/images/phonestyles/jquery-1.3.2.min.js | 200 OK Content-Length: 57254 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ipm.ac.ir
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 08 Sep 2014 23:56:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 PHP/5.3.6 mod_chroot/0.4
Content-Type: text/html;charset=utf-8
Set-Cookie: JSESSIONID=99F85CFE98E77390C13C9BAC26B3A4D6; Path=/
GET / HTTP/1.1
Host: ipm.ac.ir
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 08 Sep 2014 23:56:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 PHP/5.3.6 mod_chroot/0.4
Content-Type: text/html;charset=utf-8
Set-Cookie: JSESSIONID=99F85CFE98E77390C13C9BAC26B3A4D6; Path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: ipm.ac.ir
Referer: http://www.google.com/search?q=ipm.ac.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ipm.ac.ir
Referer: http://www.google.com/search?q=ipm.ac.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.