Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kiemdinhnn.vn
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 28 May 2014 11:04:11 GMT
Server: LiteSpeed
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kiemdinhnn.vn/xmlrpc.php
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: kiemdinhnn.vn
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 28 May 2014 11:04:11 GMT
Server: LiteSpeed
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kiemdinhnn.vn/xmlrpc.php
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: kiemdinhnn.vn
Referer: http://www.google.com/search?q=kiemdinhnn.vn
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kiemdinhnn.vn
Referer: http://www.google.com/search?q=kiemdinhnn.vn
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://kiemdinhnn.vn/ | 200 OK Content-Length: 38047 Content-Type: text/html | clean |
http://kiemdinhnn.vn/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/wp-content/plugins/flash-album-gallery/admin/js/swfobject.js?ver=2.2 | 200 OK Content-Length: 11754 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/wp-content/plugins/flash-album-gallery/admin/js/swfaddress.js?ver=2.4 | 200 OK Content-Length: 15916 Content-Type: application/javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.6.1/jquery.min.js | 200 OK Content-Length: 91342 Content-Type: text/javascript | clean |
http://www.bitcoinplus.com/js/miner.js | 200 OK Content-Length: 19329 Content-Type: application/x-javascript | clean |
http://kiemdinhnn.vn/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.50.0-2014.02.05 | 200 OK Content-Length: 16305 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.8 | 200 OK Content-Length: 9630 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/wp-includes/js/thickbox/thickbox.js?ver=3.1-20121105 | 200 OK Content-Length: 12018 Content-Type: application/javascript | clean |
http://kiemdinhnn.vn/category/gioi-thieu/ | 200 OK Content-Length: 34249 Content-Type: text/html | clean |
http://kiemdinhnn.vn/category/tin-tuc/ | 200 OK Content-Length: 35843 Content-Type: text/html | clean |
http://kiemdinhnn.vn/category/dich-vu/ | 200 OK Content-Length: 37227 Content-Type: text/html | clean |
http://kiemdinhnn.vn/category/van-ban-phap-luat/ | 200 OK Content-Length: 36738 Content-Type: text/html | clean |
http://kiemdinhnn.vn/category/thu-vien-anh/ | 200 OK Content-Length: 36670 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kiemdinhnn.vn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://kiemdinhnn.vn/
Result: kiemdinhnn.vn is not infected or malware details are not published yet.
Result: kiemdinhnn.vn is not infected or malware details are not published yet.