Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=redirecta.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://redirecta.net/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: rapidhouse.ru
Result:
GET / HTTP/1.1
Host: rapidhouse.ru
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: rapidhouse.ru
Referer: http://www.google.com/search?q=rapidhouse.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: rapidhouse.ru
Referer: http://www.google.com/search?q=rapidhouse.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://redirecta.net/ | HTTP/1.1 302 Found Connection: close Date: Fri, 27 Feb 2015 23:47:21 GMT Location: http://gatewey.net/?go= Server: nginx/1.0.15 Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.28 | clean |
http://gatewey.net/?go= | HTTP/1.1 302 Found Connection: close Date: Fri, 27 Feb 2015 23:47:21 GMT Location: http://go.redirecta.net/?tds=1434&mark=bezparametra Server: nginx/1.0.15 Vary: Accept-Encoding,User-Agent Content-Length: 661 Content-Type: text/html X-Powered-By: PHP/5.3.28 | malicious |
http://go.redirecta.net/?tds=1434&mark=bezparametra | HTTP/1.1 302 Found Connection: close Date: Fri, 27 Feb 2015 23:47:22 GMT Location: http://hotzone2nn.com/blacktube/?page=play&id=789&sid=461735546&mark=bezparametra Server: nginx/1.0.14 Content-Length: 0 Content-Type: text/html; charset=utf-8 Set-Cookie: sequence=3; expires=Sat, 28-Feb-2015 23:47:22 GMT; path=/ Set-Cookie: tds_id=1434; expires=Sat, 28-Feb-2015 23:47:22 GMT; path=/ Set-Cookie: tds_1434_id_4580=1; expires=Sat, 28-Feb-2015 23:47:22 GMT; path=/ X-Powered-By: PHP/5.3.10 | clean |
http://hotzone2nn.com/blacktube/?page=play&id=789&sid=461735546&mark=bezparametra | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Fri, 27 Feb 2015 23:47:22 GMT Pragma: no-cache Location: http://hotzonepqnn.name/blacktube?page=play&id=789&sid=461735546&mark=bezparametra Server: nginx/1.0.14 Content-Length: 3 Content-Type: text/html; charset=utf-8 Expires: Mon, 02 Mar 2015 23:47:22 GMT Set-Cookie: PHPSESSID=d4n7q29epi90m8h9gmgeppvq25; path=/ X-Powered-By: PHP/5.3.10 | malicious |
http://hotzonepqnn.name/blacktube?page=play&id=789&sid=461735546&mark=bezparametra | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=259200 Connection: close Date: Fri, 27 Feb 2015 23:47:23 GMT Location: http://hotzonepqnn.name/blacktube/?page=play&id=789&sid=461735546&mark=bezparametra Server: nginx/1.0.14 Content-Length: 185 Content-Type: text/html Expires: Mon, 02 Mar 2015 23:47:23 GMT | clean |
http://hotzonepqnn.name/blacktube/?page=play&id=789&sid=461735546&mark=bezparametra | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Fri, 27 Feb 2015 23:47:23 GMT Pragma: no-cache Location: /blacktube/?page=play&id=789&mark=bezparametra Server: nginx/1.0.14 Content-Length: 3 Content-Type: text/html; charset=utf-8 Expires: Mon, 02 Mar 2015 23:47:23 GMT Set-Cookie: PHPSESSID=nfokbrtcm10lsbeoriuguoble2; path=/ X-Powered-By: PHP/5.3.10 | clean |
http://hotzonepqnn.name/test404page.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |