Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: jana-cova.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Apr 2014 13:41:14 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.jana-cova.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: jana-cova.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Apr 2014 13:41:14 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.jana-cova.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: jana-cova.com
Referer: http://www.google.com/search?q=jana-cova.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: jana-cova.com
Referer: http://www.google.com/search?q=jana-cova.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://jana-cova.com/ | 200 OK Content-Length: 13388 Content-Type: text/html | clean |
http://jana-cova.com/test404page.js | HTTP/1.1 302 Found Cache-Control: max-age=2592000 Connection: close Date: Sat, 26 Apr 2014 13:41:16 GMT Location: http://www.pornstarangels.com/404.html Server: Apache/2.2.3 (CentOS) Vary: Accept-Encoding Content-Length: 300 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 26 May 2014 13:41:16 GMT | clean |
http://www.pornstarangels.com/404.html | 200 OK Content-Length: 6418 Content-Type: text/html | clean |
http://www.pornstarangels.com/ | 200 OK Content-Length: 11282 Content-Type: text/html | clean |
http://www.pornstarangels.com/pornstars.html | 200 OK Content-Length: 8904 Content-Type: text/html | clean |
http://www.pornstarangels.com/members | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Apr 2014 13:41:18 GMT Location: http://www.pornstarangels.com/members/ Server: Apache/2.2.3 (CentOS) Vary: Accept-Encoding Content-Length: 333 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.pornstarangels.com/members/ | HTTP/1.1 302 Found Connection: close Date: Sat, 26 Apr 2014 13:41:19 GMT Location: http://pornstarangels.com/sblogin/login.shtml/members/ Server: Apache/2.2.3 (CentOS) Vary: Accept-Encoding Content-Length: 325 Content-Type: text/html; charset=iso-8859-1 | clean |
http://pornstarangels.com/sblogin/login.shtml/members/ | 200 OK Content-Length: 3657 Content-Type: text/html | clean |
http://pornstarangels.com/sblogin/formfiller.js | 200 OK Content-Length: 1864 Content-Type: application/x-javascript | clean |
http://www.pornstarangels.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sat, 26 Apr 2014 13:41:20 GMT Location: http://www.pornstarangels.com/404.html Server: Apache/2.2.3 (CentOS) Vary: Accept-Encoding Content-Length: 309 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.pornstarangels.com/privacy.html | 200 OK Content-Length: 2918 Content-Type: text/html | clean |
http://www.pornstarangels.com/index.html | 200 OK Content-Length: 11282 Content-Type: text/html | clean |
http://www.pornstarangels.com/terms.html | 200 OK Content-Length: 7059 Content-Type: text/html | clean |
http://www.pornstarangels.com/2257.html | 200 OK Content-Length: 1433 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=jana-cova.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://jana-cova.com/
Result: jana-cova.com is not infected or malware details are not published yet.
Result: jana-cova.com is not infected or malware details are not published yet.