Scanned pages/files
Request | Server response | Status |
http://kear.org/ | 200 OK Content-Length: 4892 Content-Type: text/html | clean |
http://www.calculatorcat.com/cs/mm/ccm_b.js | 200 OK Content-Length: 3900 Content-Type: application/javascript | clean |
http://www.calculatorcat.com/cs/mm/ccm_v.js | 200 OK Content-Length: 2105 Content-Type: application/javascript | clean |
http://airliners.net/random.inc | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 22 Jul 2014 18:53:08 GMT Location: http://www.airliners.net/random.inc Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.airliners.net/random.inc | 200 OK Content-Length: 570 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<table bgcolor=black><tr><td><font size=2 color=white><center>Random Airliners.net Photo:<br></font>'); document.write('<a href="http://www.airliners.net/photo/Cub-Crafters-CC11-100/1790871/M/" target=_blank title="Untitled Cub Crafters CC11-100 Sport Cub S2"><img src="http://cdn-www.airliners.net/aviation-photos/small/1/7/8/1790871.jpg" alt="Untitled Cub Crafters CC11-100 Sport Cub S2" border="0" width="200" height="133"></a><br>'); document.write('<font size=2 color=white><center>Click photo for large version!</center></font></td></tr></table>'); Antivirus reports:
| ||
http://netwx.accuweather.com/netweatherV2.asp?zipcode=27101&lang=eng&size=4&theme=1&metric=0 | 200 OK Content-Length: 8265 Content-Type: text/javascript | clean |
http://kear.org/test404page.js | 404 Not Found Content-Length: 1148 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kear.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 22 Jul 2014 18:53:02 GMT
Accept-Ranges: bytes
ETag: "131c-4f974e92-5aeec991f766fe7b"
Server: LiteSpeed
Content-Length: 4892
Content-Type: text/html
Last-Modified: Wed, 25 Apr 2012 01:08:34 GMT
...4892 bytes of data.
GET / HTTP/1.1
Host: kear.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 22 Jul 2014 18:53:02 GMT
Accept-Ranges: bytes
ETag: "131c-4f974e92-5aeec991f766fe7b"
Server: LiteSpeed
Content-Length: 4892
Content-Type: text/html
Last-Modified: Wed, 25 Apr 2012 01:08:34 GMT
...4892 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: kear.org
Referer: http://www.google.com/search?q=kear.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kear.org
Referer: http://www.google.com/search?q=kear.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kear.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://kear.org/
Result: kear.org is not infected or malware details are not published yet.
Result: kear.org is not infected or malware details are not published yet.