Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: productos.solcess.com
Result:
GET / HTTP/1.1
Host: productos.solcess.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: productos.solcess.com
Referer: http://www.google.com/search?q=productos.solcess.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: productos.solcess.com
Referer: http://www.google.com/search?q=productos.solcess.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://svechnoy-www.10000072879.8.sunbo7.net/ | 200 OK Content-Length: 55914 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/jscss/jquery.js | 200 OK Content-Length: 177 Content-Type: application/x-javascript | clean |
http://www.sunbo.com/~lixp/js_adver/head_adver.js | 200 OK Content-Length: 544 Content-Type: application/x-javascript | clean |
http://www.sunbo.com/~lixp/js_adver/bom_adver.js | 200 OK Content-Length: 2948 Content-Type: application/x-javascript | clean |
http://v9.cnzz.com/stat.php?id=478381&web_id=478381 | 200 OK Content-Length: 9619 Content-Type: application/javascript | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/index.php?xname=PTDBO41 | 200 OK Content-Length: 55914 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=3&dname= | 200 OK Content-Length: 19746 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=4&dname= | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=1, pre-check=1 Connection: close Date: Mon, 31 Mar 2014 05:02:16 GMT Pragma: no-cache Location: http://www.infinitus.com.cn/ Server: nginx Content-Type: text/html Set-Cookie: SWSSESSID=f889ed8a5aab966927d3c659c858b175; expires=Mon, 31-Mar-2014 06:02:16 GMT Set-Cookie: _hdr_nav_=%7C4%7C%B9%AB%CB%BE%CD%F8%D5%BE%0AVCLFO41 | malicious |
http://www.infinitus.com.cn/ | 200 OK Content-Length: 1305 Content-Type: text/html | clean |
http://www.infinitus.com.cn/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=5&dname= | 200 OK Content-Length: 18534 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=6&dname= | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=1, pre-check=1 Connection: close Date: Mon, 31 Mar 2014 05:02:28 GMT Pragma: no-cache Location: http://hexun.com/ad50170168/ Server: nginx Content-Type: text/html Set-Cookie: SWSSESSID=f889ed8a5aab966927d3c659c858b175; expires=Mon, 31-Mar-2014 06:02:28 GMT Set-Cookie: _hdr_nav_=%7C6%7C%CE%D2%B5%C4%D7%AA%CC%F9%0A1DLFO41 | clean |
http://hexun.com/ad50170168/ | 200 OK Content-Length: 599 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=7&dname= | 200 OK Content-Length: 27185 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=8&dname= | 200 OK Content-Length: 44600 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=9&dname= | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=1, pre-check=1 Connection: close Date: Mon, 31 Mar 2014 05:02:32 GMT Pragma: no-cache Location: http://www.infinitus.com.cn/html/cause/ Server: nginx Content-Type: text/html Set-Cookie: SWSSESSID=f889ed8a5aab966927d3c659c858b175; expires=Mon, 31-Mar-2014 06:02:32 GMT Set-Cookie: _hdr_nav_=%7C9%7C%CA%C2%D2%B5%CE%DE%CF%DE+%0A7DLFO41 | malicious |
http://www.infinitus.com.cn/html/cause/ | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://svechnoy-www.10000072879.8.sunbo7.net/show_hdr.php?xname=PTDBO41&xpos=10&dname= | 200 OK Content-Length: 50461 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=svechnoy-www.10000072879.8.sunbo7.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://svechnoy-www.10000072879.8.sunbo7.net/
Result: svechnoy-www.10000072879.8.sunbo7.net is not infected or malware details are not published yet.
Result: svechnoy-www.10000072879.8.sunbo7.net is not infected or malware details are not published yet.