Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kdta.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.kdta.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 23 Dec 2014 08:33:11 GMT Pragma: no-cache Location: http://kdta.com/ Server: nginx/1.6.2 Vary: User-Agent,Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=203b542fa0ca47ea2904afc7a3c01911; path=/ X-Pingback: http://kdta.com/xmlrpc.php X-Powered-By: W3 Total Cache/0.9.2.4 | clean |
http://kdta.com/ | 200 OK Content-Length: 28269 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: fitology.my <!DOCTYPE html> <!--[if IE 6]> <html id="ie6" dir="ltr" lang="en-US"> <![endif]--> <!--[if IE 7]> <html id="ie7" dir="ltr" lang="en-US"> <![endif]--> <!--[if IE 8]> <html id="ie8" dir="ltr" lang="en-US"> <![endif]--> <!--[if !(IE 6) | !(IE 7) | !(IE 8) ]><!--> <html dir="ltr" lang="en-US"> <!--<![endif]--> <he ...[4413 bytes skipped]... | ||
http://122.155.168.105/ads/inpage/pub/collect.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://122.155.168.105/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kdta.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 23 Dec 2014 08:33:12 GMT
Pragma: no-cache
Server: nginx/1.6.2
Vary: User-Agent,Accept-Encoding
Content-Length: 28269
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=611309a7c1f64d12d78658c32814fdf1; path=/
X-Pingback: http://kdta.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.2.4
...28269 bytes of data.
GET / HTTP/1.1
Host: kdta.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 23 Dec 2014 08:33:12 GMT
Pragma: no-cache
Server: nginx/1.6.2
Vary: User-Agent,Accept-Encoding
Content-Length: 28269
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=611309a7c1f64d12d78658c32814fdf1; path=/
X-Pingback: http://kdta.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.2.4
...28269 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: kdta.com
Referer: http://www.google.com/search?q=kdta.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kdta.com
Referer: http://www.google.com/search?q=kdta.com
Result:
The result is similar to the first query. There are no suspicious redirects found.