Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=movies.fuckingteenvids.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://movies.fuckingteenvids.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: movies.fuckingteenvids.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 16 Sep 2014 16:40:26 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=6bd00e7b1abeb9c1d1b89fabed56d2b6; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
GET / HTTP/1.1
Host: movies.fuckingteenvids.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 16 Sep 2014 16:40:26 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=6bd00e7b1abeb9c1d1b89fabed56d2b6; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: movies.fuckingteenvids.com
Referer: http://www.google.com/search?q=movies.fuckingteenvids.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: movies.fuckingteenvids.com
Referer: http://www.google.com/search?q=movies.fuckingteenvids.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://movies.fuckingteenvids.com/ | 200 OK Content-Length: 42670 Content-Type: text/html | clean |
http://www.fuckingteenvids.com/stp/js/ftv-new/ftvjs.min.js | 200 OK Content-Length: 58573 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.7/jquery.js | 200 OK Content-Length: 252881 Content-Type: text/javascript | clean |
http://www.fuckingteenvids.com/java/jsm/jquery.lazyload-advm.min.js.jgz | 200 OK Content-Length: 4916 Content-Type: application/x-javascript | clean |
http://movies.fuckingteenvids.com/st/st.php?id=111056&url=http://moviegalls2.tinseks.com/videos8/016/?nats=NDY1OjI6Ng&p=55 | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 16:40:29 GMT Location: /cgi-bin/atc/out.cgi?s=100&c=1&u=http://moviegalls2.tinseks.com/videos8/016/?nats=NDY1OjI6Ng Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: stclick=1; expires=Wed, 17-Sep-2014 16:40:29 GMT Set-Cookie: stfirst=first_click_done; expires=Wed, 17-Sep-2014 16:40:29 GMT X-Powered-By: PHP/5.2.17-pl0-gentoo | clean |
http://movies.fuckingteenvids.com/cgi-bin/atc/out.cgi?s=100&c=1&u=http://moviegalls2.tinseks.com/videos8/016/?nats=ndy1oji6ng | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 16:40:30 GMT Location: http://moviegalls2.tinseks.com/videos8/016/?nats=ndy1oji6ng Server: Apache Vary: Accept-Encoding Content-Length: 319 Content-Type: text/html; charset=iso-8859-1 | clean |
http://moviegalls2.tinseks.com/videos8/016/?nats=ndy1oji6ng | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 16:40:30 GMT Location: http://google.com?nats=ndy1oji6ng Server: nginx Content-Type: text/html; charset=iso-8859-1 | clean |
http://google.com?nats=ndy1oji6ng/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Tue, 16 Sep 2014 16:40:30 GMT Location: http://www.google.lt/?gws_rd=cr&ei=_mcYVLrwN6POygON24CwBQ Server: gws Content-Length: 258 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.002 P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." Set-Cookie: PREF=ID=3ce49ee9bf1fb6b2:FF=0:TM=1410885630:LM=1410885630:S=RhhkU33Jiw4cTqCH; expires=Thu, 15-Sep-2016 16:40:30 GMT; path=/; domain=.google.com Set-Cookie: NID=67=Yg8bOWxjFRFgppaPmMr4-qXaCJgGaCv9czggureo6QaDcgA9hBRwz2gESO89huaBBBYaF-aJSDMNsUv92coZw8dUJCknAi5N8SycHbVF5sJCOGSzc4Ix5UB3Pdc6yB5a; expires=Wed, 18-Mar-2015 16:40:30 GMT; path=/; domain=.google.com; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/?gws_rd=cr&ei=_mcyvlrwn6poygon24cwbq | 200 OK Content-Length: 52198 Content-Type: text/html | clean |
https://www.google.lt/webhp?tab=ww | 200 OK Content-Length: 64405 Content-Type: text/html | clean |
https://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 58243 Content-Type: text/html | clean |
https://www.google.lt/webhp?hl=lt&tab=iw | 200 OK Content-Length: 64363 Content-Type: text/html | clean |
http://www.google.lt/intl/lt/options/ | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=2592000 Connection: close Date: Tue, 16 Sep 2014 16:40:33 GMT Location: http://www.google.lt/intl/lt/about/products/ Server: sffe Content-Length: 241 Content-Type: text/html; charset=UTF-8 Expires: Thu, 16 Oct 2014 16:40:33 GMT Alternate-Protocol: 80:quic,p=0.002 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/intl/lt/about/products/ | 200 OK Content-Length: 7068 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/js/gweb/analytics/autotrack.js/ | 404 Not Found Content-Length: 1471 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt/preferences?hl=lt | 200 OK Content-Length: 63646 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 52226 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=ii | 200 OK Content-Length: 52258 Content-Type: text/html | clean |