Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.koavl.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.koavl.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 12:49:22 GMT Location: http://go.oclaserver.com/entry.php?zoneid=59044&var=koavl.com Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.4-14+deb7u11 | malicious |
URL: http://go.oclaserver.com/entry.php?zoneid=59044&var=koavl.com (imitation of visitor from search engine) GET /entry.php?zoneid=59044&var=koavl.com HTTP/1.1 Host: go.oclaserver.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 27 Aug 2014 12:46:52 GMT Location: http://onclickads.net/entry.php?zoneid=59044&var=koavl.com&rocl=1 Server: nginx Content-Length: 154 Content-Type: text/html | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.koavl.com/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.koavl.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 Aug 2014 12:49:24 GMT Location: http://go.oclaserver.com/entry.php?zoneid=59044&var=koavl.com Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.4-14+deb7u11 | clean |
http://go.oclaserver.com/entry.php?zoneid=59044&var=koavl.com | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 27 Aug 2014 12:46:54 GMT Location: http://onclickads.net/entry.php?zoneid=59044&var=koavl.com&rocl=1 Server: nginx Content-Length: 154 Content-Type: text/html | clean |
http://onclickads.net/entry.php?zoneid=59044&var=koavl.com&rocl=1 | HTTP/1.1 200 OK Connection: close Date: Wed, 27 Aug 2014 12:46:54 GMT Server: nginx Content-Type: text/html | clean |
http://quick-loan.us/ | 200 OK Content-Length: 8227 Content-Type: text/html | clean |
http://d1vbm0eveofcle.cloudfront.net/scripts/js3caf.js | 200 OK Content-Length: 3490 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=koavl.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://koavl.com/
Result: koavl.com is not infected or malware details are not published yet.
Result: koavl.com is not infected or malware details are not published yet.