Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: networkbox4.blogspot.in
Result:
HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Connection: close
Date: Wed, 16 Jul 2014 05:16:30 GMT
Pragma: no-cache
Location: http://www.blogger.com/blogin.g?blogspotURL=http://networkbox4.blogspot.in/
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Alternate-Protocol: 80:quic
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
GET / HTTP/1.1
Host: networkbox4.blogspot.in
Result:
HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Connection: close
Date: Wed, 16 Jul 2014 05:16:30 GMT
Pragma: no-cache
Location: http://www.blogger.com/blogin.g?blogspotURL=http://networkbox4.blogspot.in/
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Alternate-Protocol: 80:quic
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Second query (visit from search engine):
GET / HTTP/1.1
Host: networkbox4.blogspot.in
Referer: http://www.google.com/search?q=networkbox4.blogspot.in
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: networkbox4.blogspot.in
Referer: http://www.google.com/search?q=networkbox4.blogspot.in
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://networkbox4.blogspot.in/ | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Wed, 16 Jul 2014 05:16:30 GMT Pragma: no-cache Location: http://www.blogger.com/blogin.g?blogspotURL=http://networkbox4.blogspot.in/ Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 80:quic X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.blogger.com/blogin.g?blogspoturl=http://networkbox4.blogspot.in/ | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:30 GMT Location: https://www.blogger.com/blogin.g?blogspoturl=http://networkbox4.blogspot.in/ Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:30 GMT Alternate-Protocol: 80:quic P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.blogger.com/blogin.g?blogspoturl=http://networkbox4.blogspot.in/ | 400 Bad Request Content-Length: 4728 Content-Type: text/html | clean |
https://www.blogger.com/ | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Wed, 16 Jul 2014 05:16:31 GMT Pragma: no-cache Location: https://www.blogger.com/home Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 443:quic P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.blogger.com/home | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:32 GMT Location: https://accounts.google.com/ServiceLogin?service=blogger&passive=1209600&continue=https://www.blogger.com/home&followup=https://www.blogger.com/home<mpl=start Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:32 GMT Alternate-Protocol: 443:quic P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/servicelogin?service=blogger&passive=1209600&continue=https://www.blogger.com/home&followup=https://www.blogger.com/home<mpl=start | 200 OK Content-Length: 69527 Content-Type: text/html | clean |
https://accounts.google.com/SignUp?service=blogger&continue=https%3A%2F%2Fwww.blogger.com%2Fhome<mpl=start | 200 OK Content-Length: 300938 Content-Type: text/html | clean |
https://accounts.google.com/ServiceLogin?continue=https%3A%2F%2Fwww.blogger.com%2Fhome&service=blogger<mpl=start&dsh=-1424805852962009247 | 200 OK Content-Length: 66877 Content-Type: text/html | clean |
https://accounts.google.com/TOS?loc=LT&hl=en | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, no-store Connection: close Date: Wed, 16 Jul 2014 05:16:34 GMT Pragma: no-cache Location: https://www.google.lt/intl/en/policies/terms/ Server: GSE Content-Length: 227 Content-Type: text/html; charset=UTF-8 Expires: Mon, 01-Jan-1990 00:00:00 GMT Alternate-Protocol: 443:quic Set-Cookie: GoogleAccountsLocale_session=en; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/intl/en/policies/terms/ | HTTP/1.1 200 OK Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:35 GMT Server: sffe Vary: Accept-Encoding Content-Type: text/html Expires: Wed, 16 Jul 2014 05:16:35 GMT Last-Modified: Tue, 24 Jan 2012 14:44:29 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://www.google.lt/intl/en/policies/terms/regional.html | 200 OK Content-Length: 20900 Content-Type: text/html | clean |
https://www.google.lt//www.google.com/js/google.js/ | 404 Not Found Content-Length: 1438 Content-Type: text/html | clean |
https://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1425 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
https://accounts.google.com//www.google.com/js/maia.js/ | 404 Not Found Content-Length: 23425 Content-Type: text/html | clean |
https://accounts.google.com/ | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:36 GMT Location: https://accounts.google.com/ManageAccount Server: GSE Content-Length: 223 Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:36 GMT Alternate-Protocol: 443:quic Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/manageaccount | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:36 GMT Location: https://accounts.google.com/ServiceLogin?passive=1209600&continue=https%3A%2F%2Faccounts.google.com%2Fmanageaccount&followup=https%3A%2F%2Faccounts.google.com%2Fmanageaccount Server: GSE Content-Length: 364 Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:36 GMT Alternate-Protocol: 443:quic Set-Cookie: GAPS=1:uOP13nDRTDA30A2lxeHTQuqvrTtIyA:ki7odZ7KrCGu1VAx;Path=/;Expires=Fri, 15-Jul-2016 05:16:36 GMT;Secure;HttpOnly;Priority=HIGH Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/servicelogin?passive=1209600&continue=https%3a%2f%2faccounts.google.com%2fmanageaccount&followup=https%3a%2f%2faccounts.google.com%2fmanageaccount | 200 OK Content-Length: 66652 Content-Type: text/html | clean |
https://accounts.google.com/RecoverAccount?continue=https%3A%2F%2Faccounts.google.com%2Fmanageaccount | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:37 GMT Location: https://www.google.com/accounts/recovery?hl=en&ard=AHwGkRkGASp0wLHNMwNVEt_4lit1oAPxFZpuXEA_s-bjjlrD8687p9vtl5ed8i9BRLflz0fK3ZsEHnrvPNcbILXvp9z1K0YY_TJo7uoW1Vcm7lDD_VMNIene00oN6UJRFfdTkWQzIQ4hrnkzNQDveU29Sca_hfeekA Server: GSE Content-Length: 399 Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:37 GMT Alternate-Protocol: 443:quic Set-Cookie: GAPS=1:xFSHImwQ82hU46YBmCzgZUla4BktAg:AyU2w3Wxmllzp68B;Path=/;Expires=Fri, 15-Jul-2016 05:16:37 GMT;Secure;HttpOnly;Priority=HIGH Strict-Transport-Security: max-age=10893354; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/recovery?hl=en&ard=ahwgkrkgasp0wlhnmwnvet_4lit1oapxfzpuxea_s-bjjlrd8687p9vtl5ed8i9brlflz0fk3zsehnrvpncbilxvp9z1k0yy_tjo7uow1vcm7ldd_vmniene00on6ujrffdtkwqziq4hrnkznqdveu29sca_hfeeka | HTTP/1.1 302 Moved Temporarily Cache-Control: no-cache, max-age=0, must-revalidate Connection: close Date: Wed, 16 Jul 2014 05:16:37 GMT Pragma: no-cache Location: https://www.google.com/accounts/RecoverAccount?hl=en&ard=ahwgkrkgasp0wlhnmwnvet_4lit1oapxfzpuxea_s-bjjlrd8687p9vtl5ed8i9brlflz0fk3zsehnrvpncbilxvp9z1k0yy_tjo7uow1vcm7ldd_vmniene00on6ujrffdtkwqziq4hrnkznqdveu29sca_hfeeka&arr=AHwGkRmFj9FV1m3oU4ARLUGyiB4NvWrZte78piOxVu5j0LEbV7AhIAqLasubZkYiT6D-E8jF2eP_AtH0V2gkmleus5CRyWU33iP2cWi1tKgTWJc9CD8Z58Q6UfQvD_uCgCc-yWMHUH1B Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Set-Cookie: accountrecoverylocale=en; Expires=Wed, 23-Jul-2014 05:16:37 GMT; Path=/accounts/recovery; Secure; HttpOnly Set-Cookie: S=account-recovery=uy4_oQT7dKE; Domain=.google.com; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://www.google.com/accounts/recoveraccount?hl=en&ard=ahwgkrkgasp0wlhnmwnvet_4lit1oapxfzpuxea_s-bjjlrd8687p9vtl5ed8i9brlflz0fk3zsehnrvpncbilxvp9z1k0yy_tjo7uow1vcm7ldd_vmniene00on6ujrffdtkwqziq4hrnkznqdveu29sca_hfeeka&arr=ahwgkrmfj9fv1m3ou4arlugyib4nvwrzte78pioxvu5j0lebv7ahiaqlasubzkyit6d-e8jf2ep_ath0v2gkmleus5crywu33ip2cwi1tkgtwjc9cd8z58q6ufqvd_ucgcc-ywmhuh1b | HTTP/1.1 302 Moved Temporarily Cache-Control: private, max-age=0 Connection: close Date: Wed, 16 Jul 2014 05:16:37 GMT Location: https://accounts.google.com/recoveraccount?hl=en&ard=ahwgkrkgasp0wlhnmwnvet_4lit1oapxfzpuxea_s-bjjlrd8687p9vtl5ed8i9brlflz0fk3zsehnrvpncbilxvp9z1k0yy_tjo7uow1vcm7ldd_vmniene00on6ujrffdtkwqziq4hrnkznqdveu29sca_hfeeka&arr=ahwgkrmfj9fv1m3ou4arlugyib4nvwrzte78pioxvu5j0lebv7ahiaqlasubzkyit6d-e8jf2ep_ath0v2gkmleus5crywu33ip2cwi1tkgtwjc9cd8z58q6ufqvd_ucgcc-ywmhuh1b Server: GSE Content-Length: 550 Content-Type: text/html; charset=UTF-8 Expires: Wed, 16 Jul 2014 05:16:37 GMT Set-Cookie: GoogleAccountsLocale_session=en; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
https://accounts.google.com/recoveraccount?hl=en&ard=ahwgkrkgasp0wlhnmwnvet_4lit1oapxfzpuxea_s-bjjlrd8687p9vtl5ed8i9brlflz0fk3zsehnrvpncbilxvp9z1k0yy_tjo7uow1vcm7ldd_vmniene00on6ujrffdtkwqziq4hrnkznqdveu29sca_hfeeka&arr=ahwgkrmfj9fv1m3ou4arlugyib4nvwrzte78pioxvu5j0lebv7ahiaqlasubzkyit6d-e8jf2ep_ath0v2gkmleus5crywu33ip2cwi1tkgtwjc9cd8z58q6ufqvd_ucgcc-ywmhuh1b | 400 Bad Request Content-Length: 145 Content-Type: text/html | clean |
https://accounts.google.com/SignUp?continue=https%3A%2F%2Faccounts.google.com%2Fmanageaccount | 200 OK Content-Length: 300961 Content-Type: text/html | clean |
https://accounts.google.com/ServiceLogin?continue=https%3A%2F%2Faccounts.google.com%2Fmanageaccount&dsh=2881354231592242904 | 200 OK Content-Length: 66702 Content-Type: text/html | clean |
https://accounts.google.com/SignUpWithoutGmail?dsh=2881354231592242904&continue=https%3A%2F%2Faccounts.google.com%2Fmanageaccount | 200 OK Content-Length: 300284 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=networkbox4.blogspot.in
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://networkbox4.blogspot.in/
Result: networkbox4.blogspot.in is not infected or malware details are not published yet.
Result: networkbox4.blogspot.in is not infected or malware details are not published yet.