Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tpa.or.th
Result:
GET / HTTP/1.1
Host: tpa.or.th
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: tpa.or.th
Referer: http://www.google.com/search?q=tpa.or.th
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tpa.or.th
Referer: http://www.google.com/search?q=tpa.or.th
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.tpa.or.th/ | 200 OK Content-Length: 1898 Content-Type: text/html | clean |
http://www.tpa.or.th/tpanew/default.php | 200 OK Content-Length: 31446 Content-Type: text/html | clean |
http://www.tpa.or.th/tpanew/include/jumpmenu.js | 200 OK Content-Length: 168 Content-Type: application/x-javascript | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js | 200 OK Content-Length: 85260 Content-Type: text/javascript | clean |
http://cdnjs.cloudflare.com/ajax/libs/jquery-easing/1.3/jquery.easing.min.js | 200 OK Content-Length: 5555 Content-Type: application/javascript | clean |
http://www.tpa.or.th/tpanew/../ce/slides.min.jquery.js | 200 OK Content-Length: 6784 Content-Type: application/x-javascript | clean |
http://hits.truehits.in.th/data/c0002633.js | 200 OK Content-Length: 362 Content-Type: application/x-javascript | clean |
http://www.tpa.or.th/tpanew/default_en.php | 200 OK Content-Length: 19738 Content-Type: text/html | clean |
http://apis.google.com/js/plusone.js | 200 OK Content-Length: 12487 Content-Type: application/javascript | clean |
http://platform.twitter.com/widgets.js | 200 OK Content-Length: 101649 Content-Type: application/javascript | clean |
http://static.ak.fbcdn.net/connect.php/js/FB.Share | 200 OK Content-Length: 165813 Content-Type: application/x-javascript | clean |
http://www.tpa.or.th/tpanew/default_jp.php | 200 OK Content-Length: 16262 Content-Type: text/html | clean |
http://www.tpa.or.th/tpanew/news/files/2014/NNA-News.pdf | 200 OK Content-Length: 231879 Content-Type: application/pdf | clean |
http://www.tpa.or.th/test404page.js | 404 Not Found Content-Length: 290 Content-Type: text/html | clean |
http://www.tpa.or.th/tpanew/tpapage.php?page=map-sukhumwit | 200 OK Content-Length: 15442 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tpa.or.th
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tpa.or.th/
Result: tpa.or.th is not infected or malware details are not published yet.
Result: tpa.or.th is not infected or malware details are not published yet.