Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.jiyu.tv/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.jiyu.tv Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 05 Jul 2014 00:58:07 GMT Location: http://www.xin8.org Server: Apache/2.2.15 (CentOS) Content-Length: 178 Content-Type: text/html; charset=gbk X-Powered-By: PHP/5.3.3 | suspicious |
URL: http://www.xin8.org (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.xin8.org Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sat, 05 Jul 2014 00:58:18 GMT Via: 1.0 WT263CDN-11152 (squid/3.0.STABLE20) Location: http://www.caribsoft-online.biz/templates/rhuk_solarflare_ii/images/index.php Server: Apache/2.2.22 (@RELEASE@) Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html X-Cache: MISS from WT263CDN-11152 X-Cache-Lookup: MISS from WT263CDN-11152:80 X-Powered-By: PHP/5.2.17p1 | malicious |
URL: http://www.caribsoft-online.biz/templates/rhuk_solarflare_ii/images/index.php (imitation of visitor from search engine) GET /templates/rhuk_solarflare_ii/images/index.php HTTP/1.1 Host: www.caribsoft-online.biz Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sat, 05 Jul 2014 00:58:18 GMT Location: http://avicennahealth.org/templates/beez/html/mod_poll/1/all.php Server: nginx/1.6.0 Content-Length: 0 Content-Type: text/html | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.jiyu.tv/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.jiyu.tv/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 05 Jul 2014 00:58:13 GMT Location: http://www.xin8.org/test404page.js Server: Apache/2.2.15 (CentOS) Content-Length: 208 Content-Type: text/html; charset=gbk X-Powered-By: PHP/5.3.3 | clean |
http://www.xin8.org/test404page.js | 404 Not Found Content-Length: 293 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=jiyu.tv
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://jiyu.tv/
Result: jiyu.tv is not infected or malware details are not published yet.
Result: jiyu.tv is not infected or malware details are not published yet.