Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thaiso.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://thaiso.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thaiso.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 20 Dec 2014 00:27:25 GMT
Location: http://www.thaiso.com/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=07f3f7b2fdf9f7c26ac2138732a227ce; path=/
...0 bytes of data.
GET / HTTP/1.1
Host: thaiso.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 20 Dec 2014 00:27:25 GMT
Location: http://www.thaiso.com/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=07f3f7b2fdf9f7c26ac2138732a227ce; path=/
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: thaiso.com
Referer: http://www.google.com/search?q=thaiso.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thaiso.com
Referer: http://www.google.com/search?q=thaiso.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://thaiso.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 20 Dec 2014 00:27:25 GMT Location: http://www.thaiso.com/ Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=07f3f7b2fdf9f7c26ac2138732a227ce; path=/ | clean |
http://www.thaiso.com/ | 200 OK Content-Length: 48064 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/mootools/1.11/mootools-yui-compressed.js | 200 OK Content-Length: 66079 Content-Type: text/javascript | clean |
http://thaiso.com/media/system/js/caption.js | 200 OK Content-Length: 4850 Content-Type: application/javascript | clean |
http://thaiso.com/plugins/system/hotlogin/extra/hotlogin.js | 200 OK Content-Length: 2006 Content-Type: application/javascript | clean |
http://www.thaiso.com/templates/ja_tainted/js/ja.script.js | 200 OK Content-Length: 3207 Content-Type: application/javascript | clean |
http://www.thaiso.com/templates/ja_tainted/js/ja.cssmenu.js | 200 OK Content-Length: 578 Content-Type: application/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19470 Content-Type: text/javascript | clean |
http://connect.facebook.net/en_GB/all.js | 200 OK Content-Length: 160465 Content-Type: application/x-javascript | clean |
http://thaiso.com/index.php?option=com_user&view=reset&lang=en | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 20 Dec 2014 00:27:33 GMT Location: http://www.thaiso.com/index.php?option=com_user&view=reset&lang=en Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=5e40de83dc71373167022ad17e74d5fc; path=/ | clean |
http://www.thaiso.com/index.php?option=com_user&view=reset&lang=en | 200 OK Content-Length: 17856 Content-Type: text/html | clean |
http://www.thaiso.com/media/system/js/caption.js | 200 OK Content-Length: 4850 Content-Type: application/javascript | clean |
http://thaiso.com/media/system/js/validate.js | 200 OK Content-Length: 4246 Content-Type: application/javascript | clean |
http://thaiso.com/index.php?option=com_user&view=remind&lang=en | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 20 Dec 2014 00:27:37 GMT Location: http://www.thaiso.com/index.php?option=com_user&view=remind&lang=en Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=51c96409989b2ffce0e119ab2ca2291e; path=/ | clean |
http://www.thaiso.com/index.php?option=com_user&view=remind&lang=en | 200 OK Content-Length: 17820 Content-Type: text/html | clean |
http://www.thaiso.com/media/system/js/validate.js | 200 OK Content-Length: 4246 Content-Type: application/javascript | clean |
http://thaiso.com/index.php?option=com_user&view=register&Itemid=220&lang=en | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 20 Dec 2014 00:27:40 GMT Location: http://www.thaiso.com/index.php?option=com_user&view=register&Itemid=220&lang=en Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 21dcf45b7c11137392dd404f6121cee0=c7a4a8bec8d400bfd8108d434d9f82fb; path=/ | clean |
http://www.thaiso.com/index.php?option=com_user&view=register&itemid=220&lang=en | 200 OK Content-Length: 19777 Content-Type: text/html | clean |
http://www.thaiso.com/plugins/system/hotlogin/extra/hotlogin.js | 200 OK Content-Length: 2006 Content-Type: application/javascript | clean |