Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: swiss-sexdates.ch
Result:
GET / HTTP/1.1
Host: swiss-sexdates.ch
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: swiss-sexdates.ch
Referer: http://www.google.com/search?q=swiss-sexdates.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: swiss-sexdates.ch
Referer: http://www.google.com/search?q=swiss-sexdates.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
| Request | Server response | Status |
http://www.swiss-sexdates.ch/ | 200 OK Content-Length: 5347 Content-Type: text/html | clean |
http://media.datingpartner.com/index.php?dp=4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU+SUCHST+GEILE+DATES+IN+%7BGeoIP%7D%3F&stsr=y | 200 OK Content-Length: 3386 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=7844657 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://media.datingpartner.com/test404page.js | 404 Not Found Content-Length: 1038 Content-Type: text/html | clean |
http://media.datingpartner.com/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Mon, 24 Mar 2014 11:51:52 GMT Pragma: no-cache Location: http://www.xpartner.com/?dp=&extid=dp: Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=2ac5tid7nemg9b0ujm3jqv0riphl5stv; path=/ | clean |
http://www.xpartner.com/?dp=&extid=dp: | 200 OK Content-Length: 29280 Content-Type: text/html | clean |
http://www.xpartner.com/js/window.js | 200 OK Content-Length: 6782 Content-Type: application/javascript | clean |
http://media.datingpartner.com/js/jquery-1.8.2.min.js | 404 Not Found Content-Length: 1038 Content-Type: text/html | clean |
http://media.datingpartner.com/js/dom.js | 404 Not Found Content-Length: 1038 Content-Type: text/html | clean |
http://media.datingpartner.com/js/mailcheck.js | 404 Not Found Content-Length: 1038 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=7833352 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=7832317 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=8895067 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=8962549 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://media.datingpartner.com/click.php?dp=4f7z3411&extid=dp:4f7z3411&boxX=6&boxY=1&bg=ffffff&br=1&img=1&profile=3&bgtsr=ce0019&tsr=DU SUCHST GEILE DATES IN Vilnius?&stsr=y&userID=7833625 | 200 OK Content-Length: 638 Content-Type: text/html | clean |
http://webmaster.px24.com/promotion/livecornerads.php?pp=580000&wmid=600001401_23&c=0|1|2|3|4|5|6|7|8|9|10|11|12|13|14|15|16|17|18|19&rs=0&cat=Girls&t=_blank&pos=BR&lang=de | 200 OK Content-Length: 8650 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=swiss-sexdates.ch
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://swiss-sexdates.ch/
Result: swiss-sexdates.ch is not infected or malware details are not published yet.
Result: swiss-sexdates.ch is not infected or malware details are not published yet.
