Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: saihatss.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 18 Dec 2014 17:34:17 GMT
Location: http://saihatss.info/
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1
...229 bytes of data.
GET / HTTP/1.1
Host: saihatss.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 18 Dec 2014 17:34:17 GMT
Location: http://saihatss.info/
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1
...229 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: saihatss.org
Referer: http://www.google.com/search?q=saihatss.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: saihatss.org
Referer: http://www.google.com/search?q=saihatss.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://saihatss.org/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 18 Dec 2014 17:34:17 GMT Location: http://saihatss.info/ Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 229 Content-Type: text/html; charset=iso-8859-1 | clean |
http://saihatss.info/ | 200 OK Content-Length: 43548 Content-Type: text/html | clean |
http://saihatss.info/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: text/javascript | clean |
http://saihatss.org/media/system/js/core.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:22 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/core.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=1c3c419f5493101e54f11; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=1c3c419f5493101e54f11; expires=Fri, 19-Dec-2014 17:34:22 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/core.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://www.saihatss.org/test404page.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:23 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://www.saihatss.org/test404page.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=672e53795493101fc00f6; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=672e53795493101fc00f6; expires=Fri, 19-Dec-2014 17:34:23 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://www.saihatss.org/test404page.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://saihatss.org/media/system/js/caption.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:24 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/caption.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=4e79d81d54931020ad68a; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=4e79d81d54931020ad68a; expires=Fri, 19-Dec-2014 17:34:24 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/caption.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://saihatss.org/media/system/js/mootools-more.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:25 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/mootools-more.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=534e3c435493102195ac6; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=534e3c435493102195ac6; expires=Fri, 19-Dec-2014 17:34:25 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/media/system/js/mootools-more.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://saihatss.org/templates/beez_20/javascript/md_stylechanger.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:26 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/templates/beez_20/javascript/md_stylechanger.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=2fd13271549310227c586; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=2fd13271549310227c586; expires=Fri, 19-Dec-2014 17:34:26 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/templates/beez_20/javascript/md_stylechanger.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://saihatss.org/templates/beez_20/javascript/hide.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:27 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/templates/beez_20/javascript/hide.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=1062f52d54931023648e4; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=1062f52d54931023648e4; expires=Fri, 19-Dec-2014 17:34:27 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/templates/beez_20/javascript/hide.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://maps.google.com/maps/api/js?sensor=false | 200 OK Content-Length: 4271 Content-Type: text/javascript | clean |
http://saihatss.info/modules/mod_vtem_gmap/js/jquery-1.4.2.min.js | 200 OK Content-Length: 72328 Content-Type: text/javascript | clean |
http://saihatss.org/modules/mod_lofarticlesslideshow/assets/jscript.js | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 18 Dec 2014 17:34:29 GMT Pragma: no-cache Location: http://www.saihatss.org/404.html?url=http://saihatss.org/modules/mod_lofarticlesslideshow/assets/jscript.js Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: VivvoSessionId=1fe1db075493102583b36; path=/; domain=.saihatss.org Set-Cookie: VivvoSessionId=1fe1db075493102583b36; expires=Fri, 19-Dec-2014 17:34:29 GMT; path=/; domain=.saihatss.org X-Powered-By: PHP/5.3.27 | clean |
http://www.saihatss.org/404.html?url=http://saihatss.org/modules/mod_lofarticlesslideshow/assets/jscript.js | 200 OK Content-Length: 676 Content-Type: text/html | clean |
http://saihatss.info/plugins/system/plg_ztools/plg_ztools/assets/js/lazyload.js | 200 OK Content-Length: 2150 Content-Type: text/javascript | clean |
http://saihatss.info/modules/mod_latestnews/tmpl/js/jquery.min.js | 404 Not Found Content-Length: 2674 Content-Type: text/html | clean |
http://cdn.dsultra.com/js/registrar.js | 200 OK Content-Length: 1688 Content-Type: application/x-javascript | clean |
http://saihatss.info/modules/mod_latestnews/tmpl/js/script.js | 404 Not Found Content-Length: 2674 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=saihatss.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://saihatss.org/
Result: saihatss.org is not infected or malware details are not published yet.
Result: saihatss.org is not infected or malware details are not published yet.