Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://meta-files.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: meta-files.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 27 Sep 2014 17:41:32 GMT Location: http://shecanseeyou.info/0/go.php?sid=2 Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.37 mod_bwlimited/1.4 Content-Length: 398 Content-Type: text/html; charset=iso-8859-1 | malicious |
URL: http://shecanseeyou.info/0/go.php?sid=2 (imitation of visitor from search engine) GET /0/go.php?sid=2 HTTP/1.1 Host: shecanseeyou.info Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Sat, 27 Sep 2014 17:41:32 GMT Age: 1 Location: http://www.september31.com/0/go.php?sid=2 Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | suspicious |
Scanned pages/files
Request | Server response | Status |
http://meta-files.com/ | 200 OK Content-Length: 15529 Content-Type: text/html | clean |
http://meta-files.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sat, 27 Sep 2014 17:41:32 GMT Location: http://shecanseeyou.info/0/go.php?sid=2 Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.37 mod_bwlimited/1.4 Content-Length: 374 Content-Type: text/html; charset=iso-8859-1 | malicious |
http://shecanseeyou.info/0/go.php?sid=2 | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Sat, 27 Sep 2014 17:41:33 GMT Age: 1 Location: http://www.september31.com/0/go.php?sid=2 Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://www.september31.com/0/go.php?sid=2 | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:16 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/0/go.php?sid=2 Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/0/go.php?sid=2 | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12497 Content-Type: application/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21412 Content-Type: text/javascript | clean |
http://www.google.com/coop/cse/brand?form=searchbox_018151311854596026525%3Aim7ixqvhtbg | 200 OK Content-Length: 2561 Content-Type: text/javascript | clean |
http://meta-files.com//www.blogger.com/static/v1/widgets/3274410642-widgets.js/ | HTTP/1.1 302 Found Connection: close Date: Sat, 27 Sep 2014 17:41:37 GMT Location: http://shecanseeyou.info/0/go.php?sid=2 Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.37 mod_bwlimited/1.4 Content-Length: 374 Content-Type: text/html; charset=iso-8859-1 | malicious |
http://shecanseeyou.info/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Sat, 27 Sep 2014 17:41:38 GMT Age: 0 Location: http://www.september31.com/test404page.js Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://www.september31.com/test404page.js | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:21 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/test404page.js Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/test404page.js | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/static/v1/widgets/3274410642-widgets.js/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:22 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/static/v1/widgets/3274410642-widgets.js/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/static/v1/widgets/3274410642-widgets.js/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://resources.infolinks.com/js/infolinks_main.js | 200 OK Content-Length: 2525 Content-Type: application/x-javascript | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=AdSense&widgetId=AdSense2&action=editWidget§ionId=crosscol/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:25 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=AdSense&widgetId=AdSense2&action=editWidget§ionId=crosscol/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=adsense&widgetid=adsense2&action=editwidget§ionid=crosscol/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML1&action=editWidget§ionId=main/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:26 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML1&action=editWidget§ionId=main/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=html&widgetid=html1&action=editwidget§ionid=main/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML5&action=editWidget§ionId=main/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:28 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML5&action=editWidget§ionId=main/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=html&widgetid=html5&action=editwidget§ionid=main/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=AdSense&widgetId=AdSense1&action=editWidget§ionId=sidebar/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:29 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=AdSense&widgetId=AdSense1&action=editWidget§ionId=sidebar/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=adsense&widgetid=adsense1&action=editwidget§ionid=sidebar/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML3&action=editWidget§ionId=sidebar/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:31 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML3&action=editWidget§ionId=sidebar/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=html&widgetid=html3&action=editwidget§ionid=sidebar/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML4&action=editWidget§ionId=sidebar/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:32 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML4&action=editWidget§ionId=sidebar/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=html&widgetid=html4&action=editwidget§ionid=sidebar/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
http://www.september31.com//www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML2&action=editWidget§ionId=sidebar/ | HTTP/1.1 200 OK Date: Sat, 27 Sep 2014 17:42:34 GMT Accept-Ranges: bytes ETag: "1cb6c640dccdcf1:608270" Content-Length: 41547 Content-Location: http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogID=4136017846432716564&widgetType=HTML&widgetId=HTML2&action=editWidget§ionId=sidebar/ Content-Type: text/html Last-Modified: Thu, 11 Sep 2014 16:20:08 GMT X-Powered-By: ASP.NET | clean |
http://www.september31.com/saveindex.html?404;http://www.september31.com:80/www.blogger.com/rearrange?blogid=4136017846432716564&widgettype=html&widgetid=html2&action=editwidget§ionid=sidebar/ | 200 OK Content-Length: 41547 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=meta-files.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://meta-files.com/
Result: meta-files.com is not infected or malware details are not published yet.
Result: meta-files.com is not infected or malware details are not published yet.