Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mob9.mobi
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://mob9.mobi/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: injain.co.kr
Result:
GET / HTTP/1.1
Host: injain.co.kr
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: injain.co.kr
Referer: http://www.google.com/search?q=injain.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: injain.co.kr
Referer: http://www.google.com/search?q=injain.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://mob9.mobi/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 09 Aug 2014 19:45:22 GMT Location: http://www.mob9.mobi/ Server: nginx Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.31 | clean |
http://www.mob9.mobi/ | 200 OK Content-Length: 9588 Content-Type: text/html | clean |
http://www.mob9.mobi/fileList/6007/ringtones_mp3_tones_new_bollywood/singham_returns_%282014%29/new2old/1.html | 200 OK Content-Length: 4643 Content-Type: text/html | clean |
http://www.mob9.mobi/fileList/6007/ringtones_mp3_tones_new_bollywood/singham_returns_%282014%29/download/1.html | 200 OK Content-Length: 4611 Content-Type: text/html | clean |
http://www.mob9.mobi/fileList/6007/ringtones_mp3_tones_new_bollywood/singham_returns_%282014%29/a2z/1.html | 200 OK Content-Length: 4695 Content-Type: text/html | clean |
http://www.mob9.mobi/fileDownload/65148/aata_majhi_satakli_%28angry_young_man%29.html | 200 OK Content-Length: 3545 Content-Type: text/html | clean |
http://www.mob9.mobi/files/download/id/65148 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 09 Aug 2014 19:45:24 GMT Pragma: no-cache Location: http://down.mob9.mobi/files/sfd131/65148/Aata Majhi Satakli (Angry Young Man)(Mob9.mobi).mp3 Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: SKYiTech.com=8a21efdc4199c60be527f05a7d0686af; path=/ X-Powered-By: PHP/5.4.31 | malicious |
http://down.mob9.mobi/files/sfd131/65148/aata majhi satakli (angry young man)(mob9.mobi).mp3 | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://down.mob9.mobi/test404page.js | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.mob9.mobi/fileDownload/65154/aata_majhi_satakli_%28angry_young_man%29.html | 200 OK Content-Length: 3528 Content-Type: text/html | clean |
http://www.mob9.mobi/files/download/id/65154 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 09 Aug 2014 19:45:26 GMT Pragma: no-cache Location: http://down.mob9.mobi/files/sfd131/65154/Singham Returns (MBA Swag Remix)(Mob9.mobi).mp3 Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: SKYiTech.com=c786618d16e4868e86be33e7630feecc; path=/ X-Powered-By: PHP/5.4.31 | malicious |
http://down.mob9.mobi/files/sfd131/65154/singham returns (mba swag remix)(mob9.mobi).mp3 | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.mob9.mobi/fileDownload/65156/singham_returns_%28mba_swag_remix%29.html | 200 OK Content-Length: 3463 Content-Type: text/html | clean |
http://www.mob9.mobi/files/download/id/65156 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 09 Aug 2014 19:45:27 GMT Pragma: no-cache Location: http://down.mob9.mobi/files/sfd131/65156/Singham Returns Theme Song(Mob9.mobi).mp3 Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: SKYiTech.com=1b4ea016740f09e34481dffc651938dd; path=/ X-Powered-By: PHP/5.4.31 | malicious |
http://down.mob9.mobi/files/sfd131/65156/singham returns theme song(mob9.mobi).mp3 | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.mob9.mobi/fileDownload/65155/singham_returns_theme_song.html | 200 OK Content-Length: 3499 Content-Type: text/html | clean |
http://www.mob9.mobi/files/download/id/65155 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 09 Aug 2014 19:45:28 GMT Pragma: no-cache Location: http://down.mob9.mobi/files/sfd131/65155/Singham Returns Theme (Shlok)(Mob9.mobi).mp3 Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: SKYiTech.com=297332f382385258824ed8243abd0357; path=/ X-Powered-By: PHP/5.4.31 | malicious |
http://down.mob9.mobi/files/sfd131/65155/singham returns theme (shlok)(mob9.mobi).mp3 | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.mob9.mobi/fileDownload/65151/singham_returns_theme_%28shlok%29.html | 200 OK Content-Length: 3451 Content-Type: text/html | clean |
http://www.mob9.mobi/files/download/id/65151 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 09 Aug 2014 19:45:29 GMT Pragma: no-cache Location: http://down.mob9.mobi/files/sfd131/65151/Kuch Toh Hua Hai (Music)(Mob9.mobi).mp3 Server: nginx Vary: Accept-Encoding Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: SKYiTech.com=9bce3c43640ab1f9a71957214615a96a; path=/ X-Powered-By: PHP/5.4.31 | malicious |
http://down.mob9.mobi/files/sfd131/65151/kuch toh hua hai (music)(mob9.mobi).mp3 | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |