Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sanal.pro
Result:
HTTP/1.1 200 OK
Cache-Control: private, must-revalidate
Connection: close
Date: Thu, 12 Jun 2014 23:54:06 GMT
Accept-Ranges: bytes
ETag: "1ba41-539987fe-a0a27db29b1a747c"
Server: LiteSpeed
Content-Length: 113217
Content-Type: text/html
Last-Modified: Thu, 12 Jun 2014 10:59:10 GMT
...113217 bytes of data.
GET / HTTP/1.1
Host: sanal.pro
Result:
HTTP/1.1 200 OK
Cache-Control: private, must-revalidate
Connection: close
Date: Thu, 12 Jun 2014 23:54:06 GMT
Accept-Ranges: bytes
ETag: "1ba41-539987fe-a0a27db29b1a747c"
Server: LiteSpeed
Content-Length: 113217
Content-Type: text/html
Last-Modified: Thu, 12 Jun 2014 10:59:10 GMT
...113217 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sanal.pro
Referer: http://www.google.com/search?q=sanal.pro
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sanal.pro
Referer: http://www.google.com/search?q=sanal.pro
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://sanal.pro/ | HTTP/1.1 200 OK Cache-Control: private, must-revalidate Connection: close Date: Thu, 12 Jun 2014 23:54:06 GMT Accept-Ranges: bytes ETag: "1ba41-539987fe-a0a27db29b1a747c" Server: LiteSpeed Content-Length: 113217 Content-Type: text/html Last-Modified: Thu, 12 Jun 2014 10:59:10 GMT | clean |
http://sanal.pro/index.php?action=antiddos | 200 OK Content-Length: 9741 Content-Type: text/html | clean |
http://sanal.pro/jscripts/prototype.js?ver=1603 | 200 OK Content-Length: 180853 Content-Type: application/javascript | clean |
http://sanal.pro/jscripts/general.js?ver=1603 | 200 OK Content-Length: 17851 Content-Type: application/javascript | clean |
http://sanal.pro/jscripts/popup_menu.js?ver=1600 | 200 OK Content-Length: 2648 Content-Type: application/javascript | clean |
http://sanal.pro/index.php | 200 OK Content-Length: 9686 Content-Type: text/html | clean |
http://sanal.pro/search.php | 200 OK Content-Length: 9450 Content-Type: text/html | clean |
http://sanal.pro/jscripts/autocomplete.js?ver=1400 | 200 OK Content-Length: 11789 Content-Type: application/javascript | clean |
http://sanal.pro/memberlist.php | 200 OK Content-Length: 24256 Content-Type: text/html | clean |
http://sanal.pro/calendar.php | HTTP/1.1 301 Moved Permanently Cache-Control: private, must-revalidate Connection: close Date: Thu, 12 Jun 2014 23:54:10 GMT Location: http://sanal.pro/calendar.php?calendar=0 Server: LiteSpeed Content-Length: 0 Content-Type: text/html Set-Cookie: mybb[lastvisit]=1402617250; expires=Fri, 12-Jun-2015 23:54:10 GMT; path=/; domain=.sanal.pro Set-Cookie: mybb[lastactive]=1402617250; expires=Fri, 12-Jun-2015 23:54:10 GMT; path=/; domain=.sanal.pro Set-Cookie: sid=93a9f21ffc04ead44d2d52a9d0922462; path=/; domain=.sanal.pro; HttpOnly X-Powered-By: PHP/5.3.28 | clean |
http://sanal.pro/calendar.php?calendar=0 | 404 Not Found Content-Length: 6264 Content-Type: text/html | clean |
http://linkhelp.clients.google.com/tbproxy/lh/wm/fixurl.js | 200 OK Content-Length: 47623 Content-Type: text/javascript | clean |
http://sanal.pro/misc.php?action=help | 200 OK Content-Length: 8612 Content-Type: text/html | clean |
http://sanal.pro/member.php?action=login | 200 OK Content-Length: 7036 Content-Type: text/html | clean |
http://sanal.pro/member.php?action=register | 200 OK Content-Length: 8771 Content-Type: text/html | clean |
http://sanal.pro/archive/index.php | 200 OK Content-Length: 1983 Content-Type: text/html | clean |
http://sanal.pro/archive/index.php/forum-1.html | 200 OK Content-Length: 2152 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sanal.pro
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sanal.pro/
Result: sanal.pro is not infected or malware details are not published yet.
Result: sanal.pro is not infected or malware details are not published yet.