Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=m.pslegal.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://m.pslegal.org/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: m.pslegal.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Close
Date: Fri, 19 Sep 2014 19:09:43 GMT
Pragma: no-cache
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=tqklovtv3it5npiig0p1p2n9i4; path=/
Set-Cookie: mfp=tqklovtv3it5npiig0p1p2n9i4; expires=Sat, 19-Sep-2015 19:09:43 GMT; path=/; domain=m.pslegal.org
X-Powered-By: PHP/5.3.2-1ubuntu4.11
GET / HTTP/1.1
Host: m.pslegal.org
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Close
Date: Fri, 19 Sep 2014 19:09:43 GMT
Pragma: no-cache
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=tqklovtv3it5npiig0p1p2n9i4; path=/
Set-Cookie: mfp=tqklovtv3it5npiig0p1p2n9i4; expires=Sat, 19-Sep-2015 19:09:43 GMT; path=/; domain=m.pslegal.org
X-Powered-By: PHP/5.3.2-1ubuntu4.11
Second query (visit from search engine):
GET / HTTP/1.1
Host: m.pslegal.org
Referer: http://www.google.com/search?q=m.pslegal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: m.pslegal.org
Referer: http://www.google.com/search?q=m.pslegal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://m.pslegal.org/ | 200 OK Content-Length: 13045 Content-Type: text/html | clean |
http://m.pslegal.org//ajax.googleapis.com/ajax/libs/jquery/2.1.0/jquery.min.js/ | HTTP/1.1 302 Found Connection: Close Date: Fri, 19 Sep 2014 19:09:44 GMT Location: http://notfound.prohost.mobi Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/ | 200 OK Content-Length: 11387 Content-Type: text/html | clean |
http://notfound.prohost.mobi//ajax.googleapis.com/ajax/libs/jquery/2.1.0/jquery.min.js/ | HTTP/1.1 302 Found Connection: Close Date: Fri, 19 Sep 2014 19:09:45 GMT Location: http://notfound.prohost.mobi Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/test404page.js | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Close Date: Fri, 19 Sep 2014 19:09:45 GMT Pragma: no-cache Location: /notfound/7608ao5osqc1daoc7pvj9l3go6/ Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=7608ao5osqc1daoc7pvj9l3go6; path=/ Set-Cookie: mfp=7608ao5osqc1daoc7pvj9l3go6; expires=Sat, 19-Sep-2015 19:09:45 GMT; path=/; domain=notfound.prohost.mobi X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/notfound/7608ao5osqc1daoc7pvj9l3go6/ | 200 OK Content-Length: 11064 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/geo.js | 200 OK Content-Length: 8445 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/lib/js/gps.js | 200 OK Content-Length: 1269 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1411153786 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=cdijiqsbum517pgkl6nailmo90 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1411153788 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=hr42p50cptcqmnmeqid51fa9f4 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1411153789 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=aerpra8v0ma5q3n64o7aotc9r1 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1411153790 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=1vcb9ev2se06l5ga3l85cklev3 | 200 OK Content-Length: 11420 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1411153791 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=0b9nai78hhpjifuicn6a8s6vt1 | 200 OK Content-Length: 11420 Content-Type: text/html | clean |