Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: polaris-software.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Apr 2014 19:02:07 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 27 Apr 2014 19:02:08 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3d4cd977c16767096e3530b6a0080944=4c7nhp5latfmotrjiiddjeh2s0; path=/
Set-Cookie: ja_purity_tpl=ja_purity; expires=Fri, 17-Apr-2015 19:02:08 GMT; path=/
GET / HTTP/1.1
Host: polaris-software.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Apr 2014 19:02:07 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 27 Apr 2014 19:02:08 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3d4cd977c16767096e3530b6a0080944=4c7nhp5latfmotrjiiddjeh2s0; path=/
Set-Cookie: ja_purity_tpl=ja_purity; expires=Fri, 17-Apr-2015 19:02:08 GMT; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: polaris-software.com
Referer: http://www.google.com/search?q=polaris-software.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: polaris-software.com
Referer: http://www.google.com/search?q=polaris-software.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://polaris-software.com/ | 200 OK Content-Length: 23293 Content-Type: text/html | clean |
http://polaris-software.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: text/javascript | clean |
http://polaris-software.com/templates/ja_purity/js/ja.script.js | 200 OK Content-Length: 3207 Content-Type: text/javascript | clean |
http://polaris-software.com/templates/ja_purity/js/ja.rightcol.js | 200 OK Content-Length: 1695 Content-Type: text/javascript | clean |
http://polaris-software.com/index.php | 200 OK Content-Length: 23293 Content-Type: text/html | clean |
http://polaris-software.com/index.php?option=com_mailto&tmpl=component&link=d19d40b4fe55727104555c0226b550cd1099428e | 200 OK Content-Length: 2563 Content-Type: text/html | clean |
http://polaris-software.com/test404page.js | 404 Not Found Content-Length: 2445 Content-Type: text/html | clean |
http://cdn.dsultra.com/js/registrar.js | 200 OK Content-Length: 1652 Content-Type: application/x-javascript | clean |
http://polaris-software.com/images/stories/video-downloader.jpg | 200 OK Content-Length: 48332 Content-Type: image/jpeg | clean |
http://polaris-software.com/media/EVDSetup.exe | 200 OK Content-Length: 158192 Content-Type: application/octet-stream | clean |
http://polaris-software.com/index.php?option=com_mailto&tmpl=component&link=8673202c038722b0d6c2c51d26a167a5a1129c61 | 200 OK Content-Length: 2563 Content-Type: text/html | clean |
http://polaris-software.com/images/stories/oneclick.jpg | 200 OK Content-Length: 54447 Content-Type: image/jpeg | clean |
http://polaris-software.com/media/oneclick-mp4.exe | 200 OK Content-Length: 301872 Content-Type: application/octet-stream | clean |
http://polaris-software.com/media/oneclick-avi.exe | 200 OK Content-Length: 300960 Content-Type: application/octet-stream | clean |
http://polaris-software.com/media/oneclick-flv.exe | 200 OK Content-Length: 300960 Content-Type: application/octet-stream | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=polaris-software.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://polaris-software.com/
Result: polaris-software.com is not infected or malware details are not published yet.
Result: polaris-software.com is not infected or malware details are not published yet.