Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ixxx.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 12 Jun 2015 19:24:55 GMT
Via: 1.1 varnish
Age: 0
Location: http://www.ixxx.com/
Server: Apache
Content-Type: text/html; charset=iso-8859-1
X-Varnish: 980756439
GET / HTTP/1.1
Host: ixxx.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 12 Jun 2015 19:24:55 GMT
Via: 1.1 varnish
Age: 0
Location: http://www.ixxx.com/
Server: Apache
Content-Type: text/html; charset=iso-8859-1
X-Varnish: 980756439
Second query (visit from search engine):
GET / HTTP/1.1
Host: ixxx.com
Referer: http://www.google.com/search?q=ixxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ixxx.com
Referer: http://www.google.com/search?q=ixxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ixxx.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Jun 2015 19:24:55 GMT Via: 1.1 varnish Age: 0 Location: http://www.ixxx.com/ Server: Apache Content-Type: text/html; charset=iso-8859-1 X-Varnish: 980756439 | clean |
http://www.ixxx.com/ | 200 OK Content-Length: 300696 Content-Type: text/html | clean |
http://assetfiles.com/js/jquery-1.9.1.min.js | 200 OK Content-Length: 92629 Content-Type: application/x-javascript | clean |
http://assetfiles.com/js/fancybox-2.1.4/jquery.fancybox.pack.js?v=2.1.4 | 200 OK Content-Length: 22595 Content-Type: application/x-javascript | clean |
http://assetfiles.com/ixxx.com/js/uikit.min.js | 200 OK Content-Length: 34274 Content-Type: application/x-javascript | clean |
http://ixxx.com/?lid=1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Jun 2015 19:24:57 GMT Via: 1.1 varnish Age: 0 Location: http://www.ixxx.com/?lid=1 Server: Apache Content-Type: text/html; charset=iso-8859-1 X-Varnish: 980757213 | clean |
http://www.ixxx.com/?lid=1 | 200 OK Content-Length: 300696 Content-Type: text/html | clean |
http://www.ixxx.com/search/?rs=1&lid=1 | 200 OK Content-Length: 300024 Content-Type: text/html | clean |
http://assetfiles.com/js/jquery.base64.js | 200 OK Content-Length: 4498 Content-Type: application/x-javascript | clean |
http://assetfiles.com/js/jquery.cookie.js | 200 OK Content-Length: 3121 Content-Type: application/x-javascript | clean |
http://assetfiles.com/ixxx.com/js/uikit.js | 200 OK Content-Length: 70465 Content-Type: application/x-javascript | clean |
http://www.assetfiles.com/js/jquery.hoverIntent.minified.js | 200 OK Content-Length: 1390 Content-Type: application/x-javascript | clean |
http://www.assetfiles.com/js/guide_box-0.9.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://www.ixxx.com/search/?lid=1 | 200 OK Content-Length: 302144 Content-Type: text/html | clean |
http://www.ixxx.com/search/ | 200 OK Content-Length: 302144 Content-Type: text/html | clean |
http://www.ixxx.com/search/?q=&lid=1 | 200 OK Content-Length: 302144 Content-Type: text/html | clean |
http://www.ixxx.com/search/?q=&p=1&lid=1 | 200 OK Content-Length: 300696 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ixxx.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ixxx.com/
Result: ixxx.com is not infected or malware details are not published yet.
Result: ixxx.com is not infected or malware details are not published yet.