Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: twens.ch
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 17:44:59 GMT
Via: 1.1 varnish
Accept-Ranges: bytes
Age: 0
Location: http://www.twens.ch
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 301
Content-Type: text/html; charset=iso-8859-1
X-Varnish: 1329075211
...301 bytes of data.
GET / HTTP/1.1
Host: twens.ch
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 17:44:59 GMT
Via: 1.1 varnish
Accept-Ranges: bytes
Age: 0
Location: http://www.twens.ch
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 301
Content-Type: text/html; charset=iso-8859-1
X-Varnish: 1329075211
...301 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: twens.ch
Referer: http://www.google.com/search?q=twens.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: twens.ch
Referer: http://www.google.com/search?q=twens.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://twens.ch/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:44:59 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.twens.ch Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 301 Content-Type: text/html; charset=iso-8859-1 X-Varnish: 1329075211 | clean |
http://www.twens.ch/ | 200 OK Content-Length: 40697 Content-Type: text/html | clean |
http://mobijs.cam-content.com/smartphonecheck.js?SystemID=xxx-sexportal-com | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://mobijs.cam-content.com/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://pas.private4.com/popup/video/?wid=374&col1=990000&col2=000000&col3=ffffff&sx=1&sy=2&mod=16&typ=2 | 200 OK Content-Length: 2976 Content-Type: text/html | clean |
http://pas.private4.com/popup/video/\" | 404 Not Found Content-Length: 365 Content-Type: text/html | clean |
http://www.sex-webcam.ch/promo/teaser2.php?moid=20&promid=8750 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 17:45:01 GMT Location: http://www.sex-webcam.ch/?moid=20&promid=8750 Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 257 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.sex-webcam.ch/?moid=20&promid=8750 | HTTP/1.1 302 Found Connection: close Date: Sat, 04 Oct 2014 17:45:02 GMT Location: http://www.momo-net.com/?moid=20&promid=8750 Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Set-Cookie: refcookie=norefer; expires=Sun, 05-Oct-2014 17:45:02 GMT; path=/ | clean |
http://www.momo-net.com/?moid=20&promid=8750 | 200 OK Content-Length: 3935 Content-Type: text/html | clean |
http://delivery.trafficfabrik.com/ads/ads.php?index=1&t=MTA5MzsxNjAyO3ZlcnRpY2FsLndpZGVfc2t5c2NyYXBlcg==&tf_partner=1068 | 200 OK Content-Length: 10619 Content-Type: application/javascript | clean |
http://delivery.trafficfabrik.com/ads/ads.php?index=1&t=MTA5MzsxNTk5O2hvcml6b250YWwuYmFubmVyXzM=&tf_partner=1068 | 200 OK Content-Length: 10631 Content-Type: application/javascript | clean |
http://delivery.trafficfabrik.com/ads/ads.php?index=1&t=MTA5MzsxNTk3O2hvcml6b250YWwubGVhZGVyYm9hcmQ=&tf_partner=1068 | 200 OK Content-Length: 10626 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=twens.ch
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://twens.ch/
Result: twens.ch is not infected or malware details are not published yet.
Result: twens.ch is not infected or malware details are not published yet.