Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: starpizzasite.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 14 Sep 2014 19:42:37 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 14 Sep 2014 19:42:38 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d4dad6935f632ac35975e3001dc7bbe8=9btcbsfq37nicpbainq5q3a0m2; path=/
GET / HTTP/1.1
Host: starpizzasite.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 14 Sep 2014 19:42:37 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 14 Sep 2014 19:42:38 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d4dad6935f632ac35975e3001dc7bbe8=9btcbsfq37nicpbainq5q3a0m2; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: starpizzasite.com
Referer: http://www.google.com/search?q=starpizzasite.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: starpizzasite.com
Referer: http://www.google.com/search?q=starpizzasite.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://starpizzasite.com/ | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 14 Sep 2014 19:42:37 GMT Pragma: no-cache Server: Apache Content-Type: text/html; charset=utf-8 Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Sun, 14 Sep 2014 19:42:38 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: d4dad6935f632ac35975e3001dc7bbe8=9btcbsfq37nicpbainq5q3a0m2; path=/ | clean |
http://starpizzasite.prohost.mobi/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Close Date: Sun, 14 Sep 2014 19:42:39 GMT Pragma: no-cache Location: http://notfound.prohost.mobi/ Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=s467nu27oid5akk6v522slcnq6; path=/ Set-Cookie: mfp=s467nu27oid5akk6v522slcnq6; expires=Mon, 14-Sep-2015 19:42:39 GMT; path=/; domain=starpizzasite.prohost.mobi X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/ | 200 OK Content-Length: 11387 Content-Type: text/html | clean |
http://notfound.prohost.mobi//ajax.googleapis.com/ajax/libs/jquery/2.1.0/jquery.min.js/ | HTTP/1.1 302 Found Connection: Close Date: Sun, 14 Sep 2014 19:42:40 GMT Location: http://notfound.prohost.mobi Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/test404page.js | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Close Date: Sun, 14 Sep 2014 19:42:40 GMT Pragma: no-cache Location: /notfound/nat75u6bmas6a1u4mgli822ss3/ Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=nat75u6bmas6a1u4mgli822ss3; path=/ Set-Cookie: mfp=nat75u6bmas6a1u4mgli822ss3; expires=Mon, 14-Sep-2015 19:42:40 GMT; path=/; domain=notfound.prohost.mobi X-Powered-By: PHP/5.3.2-1ubuntu4.11 | clean |
http://notfound.prohost.mobi/notfound/nat75u6bmas6a1u4mgli822ss3/ | 200 OK Content-Length: 11065 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/geo.js | 200 OK Content-Length: 8445 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/lib/js/gps.js | 200 OK Content-Length: 1269 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1410723761 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=c1jij6d4kfsfirj8v0jf93cvv5 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1410723763 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=i4u1isid2c61thv1p03a8vfge5 | 200 OK Content-Length: 11420 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1410723764 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=59i2d2hij8em1h7cs94amuhv06 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/?t=k9r8hl2p5tq7dh7mu0spfqdna5 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1410723765 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=qtvt4tr899sdccv47q9sdpdqp5 | 200 OK Content-Length: 11421 Content-Type: text/html | clean |
http://notfound.prohost.mobi/lib/js/atrk.js?v=1410723766 | 200 OK Content-Length: 3893 Content-Type: application/javascript | clean |
http://notfound.prohost.mobi/?t=7nam3g62ntdcfpouj42ufe53f2 | 200 OK Content-Length: 11420 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=starpizzasite.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://starpizzasite.com/
Result: starpizzasite.com is not infected or malware details are not published yet.
Result: starpizzasite.com is not infected or malware details are not published yet.