Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lnftp.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: communicate2connect.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600, public, must-revalidate, proxy-revalidate
Connection: close
Date: Fri, 09 Jan 2015 17:14:29 GMT
Pragma: public
Accept-Ranges: bytes
Server: Apache
Content-Length: 56352
Content-Type: text/html
Expires: Fri, 09 Jan 2015 18:14:29 GMT
Last-Modified: Fri, 01 Jun 2012 09:38:02 GMT
...56352 bytes of data.
GET / HTTP/1.1
Host: communicate2connect.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600, public, must-revalidate, proxy-revalidate
Connection: close
Date: Fri, 09 Jan 2015 17:14:29 GMT
Pragma: public
Accept-Ranges: bytes
Server: Apache
Content-Length: 56352
Content-Type: text/html
Expires: Fri, 09 Jan 2015 18:14:29 GMT
Last-Modified: Fri, 01 Jun 2012 09:38:02 GMT
...56352 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: communicate2connect.com
Referer: http://www.google.com/search?q=communicate2connect.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: communicate2connect.com
Referer: http://www.google.com/search?q=communicate2connect.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.lnftp.com/ | HTTP/1.1 200 OK Date: Tue, 16 Dec 2014 19:01:52 GMT Accept-Ranges: bytes ETag: "12c81c30c217d01:6a4" Server: Microsoft-IIS/6.0 Content-Length: 6840 Content-Location: http://www.lnftp.com/index.html Content-Type: text/html Last-Modified: Sun, 14 Dec 2014 17:19:59 GMT X-Powered-By: ASP.NET | clean |
http://www.lnftp.com/index.html | 200 OK Content-Length: 6840 Content-Type: text/html | clean |
http://www.lnftp.com/js/jquery.min.js | 200 OK Content-Length: 85260 Content-Type: application/x-javascript | clean |
http://www.lnftp.com/js/common.js | 200 OK Content-Length: 12552 Content-Type: application/x-javascript | clean |
http://www.lnftp.com/ylmf_1.html | 200 OK Content-Length: 8278 Content-Type: text/html | clean |
http://www.lnftp.com/shendu_1.html | 200 OK Content-Length: 8107 Content-Type: text/html | clean |
http://www.lnftp.com/fqhy_1.html | 200 OK Content-Length: 8120 Content-Type: text/html | clean |
http://www.lnftp.com/lbjy_1.html | 200 OK Content-Length: 8199 Content-Type: text/html | clean |
http://www.lnftp.com/diannao.html | 200 OK Content-Length: 8439 Content-Type: text/html | clean |
http://www.lnftp.com/win7_1.html | 200 OK Content-Length: 8341 Content-Type: text/html | clean |
http://www.lnftp.com/down/win7.html | HTTP/1.1 302 Redirect Date: Tue, 16 Dec 2014 19:02:05 GMT Location: http://dx.gelizz.com/DNGS Ghost Win7 32bit V2014.iso Server: Microsoft-IIS/6.0 Content-Length: 175 Content-Type: text/html X-Powered-By: ASP.NET | malicious |
http://dx.gelizz.com/dngs ghost win7 32bit v2014.iso | 200 OK Content-Length: 301928 Content-Type: isofile | clean |
http://dx.gelizz.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://www.lnftp.com/down/wtwin7.html | HTTP/1.1 302 Redirect Date: Tue, 16 Dec 2014 19:02:10 GMT Location: http://58.241.243.85:888/DNGS Ghost Win7 32bit V2014.iso Server: Microsoft-IIS/6.0 Content-Length: 179 Content-Type: text/html X-Powered-By: ASP.NET | clean |
http://58.241.243.85:888/dngs ghost win7 32bit v2014.iso | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.lnftp.com/down/dngs.html | HTTP/1.1 302 Redirect Date: Tue, 16 Dec 2014 19:02:16 GMT Location: http://dx.gelizz.com/DNGS_GHOST_XP SP3 V2014.iso Server: Microsoft-IIS/6.0 Content-Length: 171 Content-Type: text/html X-Powered-By: ASP.NET | malicious |
http://dx.gelizz.com/dngs_ghost_xp sp3 v2014.iso | 200 OK Content-Length: 302212 Content-Type: isofile | clean |
http://www.lnftp.com/down/wtdngs.html | HTTP/1.1 302 Redirect Date: Tue, 16 Dec 2014 19:02:20 GMT Location: http://58.241.243.85:888/DNGS_GHOST_XP SP3 V2014.iso Server: Microsoft-IIS/6.0 Content-Length: 175 Content-Type: text/html X-Powered-By: ASP.NET | clean |
http://58.241.243.85:888/dngs_ghost_xp sp3 v2014.iso | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.lnftp.com/down/luobo.html | HTTP/1.1 302 Redirect Date: Tue, 16 Dec 2014 19:02:26 GMT Location: http://dx.gelizz.com/LuoBO_GhostXP SP3 V2014.iso Server: Microsoft-IIS/6.0 Content-Length: 171 Content-Type: text/html X-Powered-By: ASP.NET | malicious |
http://dx.gelizz.com/luobo_ghostxp sp3 v2014.iso | 200 OK Content-Length: 300752 Content-Type: isofile | clean |