Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: registrocivil.chiapas.gob.mx
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 21 Aug 2015 21:05:38 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=iso-8859-1
GET / HTTP/1.1
Host: registrocivil.chiapas.gob.mx
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 21 Aug 2015 21:05:38 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=iso-8859-1
Second query (visit from search engine):
GET / HTTP/1.1
Host: registrocivil.chiapas.gob.mx
Referer: http://www.google.com/search?q=registrocivil.chiapas.gob.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: registrocivil.chiapas.gob.mx
Referer: http://www.google.com/search?q=registrocivil.chiapas.gob.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://registrocivil.chiapas.gob.mx/ | 200 OK Content-Length: 20440 Content-Type: text/html | clean |
http://www.registrocivil.chiapas.gob.mx/js/jquery.js | 200 OK Content-Length: 92791 Content-Type: application/javascript | clean |
http://www.registrocivil.chiapas.gob.mx/js/bootstrap.js | 200 OK Content-Length: 61764 Content-Type: application/javascript | clean |
http://registrocivil.chiapas.gob.mx/../regnacimiento/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/test404page.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 21 Aug 2015 21:05:42 GMT Location: http://www.registrocivil.chiapas.gob.mx/error/2 Server: Apache Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.registrocivil.chiapas.gob.mx/error/2 | 200 OK Content-Length: 688 Content-Type: text/html | clean |
http://www.registrocivil.chiapas.gob.mx/error/../mapa | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 21 Aug 2015 21:05:44 GMT Location: http://www.registrocivil.chiapas.gob.mx/error/2 Server: Apache Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.registrocivil.chiapas.gob.mx/test404page.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 21 Aug 2015 21:05:45 GMT Location: http://www.registrocivil.chiapas.gob.mx/error/2 Server: Apache Content-Type: text/html; charset=iso-8859-1 | clean |
http://registrocivil.chiapas.gob.mx/../regmatrimonio/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../regdefuncion/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../regdivorcio/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../reconocimiento/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../adopcion/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../inscripcion/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../consulta-curp/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../acercadelsitio/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../webmaster/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
http://registrocivil.chiapas.gob.mx/../politica-privacidad/ | 400 Bad Request Content-Length: 1792 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=registrocivil.chiapas.gob.mx
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://registrocivil.chiapas.gob.mx/
Result: registrocivil.chiapas.gob.mx is not infected or malware details are not published yet.
Result: registrocivil.chiapas.gob.mx is not infected or malware details are not published yet.