Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: txbra.org
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Date: Fri, 03 Oct 2014 18:33:22 GMT
Location: /home/index.asp
Server: Microsoft-IIS/6.0
Content-Length: 136
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCQABTTQ=KIOEDBEDNDBJIBPDICCDLMHG; path=/
X-Powered-By: ASP.NET
...136 bytes of data.
GET / HTTP/1.1
Host: txbra.org
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Date: Fri, 03 Oct 2014 18:33:22 GMT
Location: /home/index.asp
Server: Microsoft-IIS/6.0
Content-Length: 136
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCQABTTQ=KIOEDBEDNDBJIBPDICCDLMHG; path=/
X-Powered-By: ASP.NET
...136 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: txbra.org
Referer: http://www.google.com/search?q=txbra.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: txbra.org
Referer: http://www.google.com/search?q=txbra.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://txbra.org/ | HTTP/1.1 302 Object moved Cache-Control: private Date: Fri, 03 Oct 2014 18:33:22 GMT Location: /home/index.asp Server: Microsoft-IIS/6.0 Content-Length: 136 Content-Type: text/html Set-Cookie: ASPSESSIONIDQCQABTTQ=KIOEDBEDNDBJIBPDICCDLMHG; path=/ X-Powered-By: ASP.NET | clean |
http://txbra.org/home/index.asp | 200 OK Content-Length: 12787 Content-Type: text/html | clean |
http://txbra.org/includes/jquery-latest.js | 200 OK Content-Length: 120763 Content-Type: application/x-javascript | clean |
http://txbra.org/includes/thickbox.js | 200 OK Content-Length: 11639 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.4/jquery.min.js | 200 OK Content-Length: 78601 Content-Type: text/javascript | clean |
http://txbra.org/home/ | 200 OK Content-Length: 12787 Content-Type: text/html | clean |
http://txbra.org/events/ | 200 OK Content-Length: 31719 Content-Type: text/html | clean |
http://txbra.org/results14/ | 200 OK Content-Length: 12755 Content-Type: text/html | clean |
http://txbra.org/organization/ | 200 OK Content-Length: 8211 Content-Type: text/html | clean |
http://txbra.org/forum3/upgrade.asp | 200 OK Content-Length: 5017 Content-Type: text/html | clean |
http://txbra.org/forum3/ | 200 OK Content-Length: 11715 Content-Type: text/html | clean |
http://www.gvisit.com/record.php?sid=cc9dea87d8638e962a4bccb38cb3c6c1 | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Keep-Alive Date: Fri, 03 Oct 2014 18:34:07 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding,User-Agent Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=126 Set-Cookie: gvc=912vr1599068471125639; expires=Wed, 02-Oct-2019 18:34:07 GMT; path=/; domain=www.gvisit.com; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKrfIMFkSaoTSqKmC+BrghK0CpDHc0MuVzmMHin8LIORhpXbped+iYhSnZurWnEO0zcKcVIrzp026LVc5pMB9bUCAwEAAQ==_E7puBrOlPyWiAEkINf+gSf6f21ewggxYjvYs7OnpBarg6PRZ/Fqd8oz8KYwkfRBNAAPSmp12oWUZLF15E8z4Eg== | clean |
http://www.gvisit.com/rg-erdr.php?_rpo=t | HTTP/1.1 302 Found Connection: Keep-Alive Date: Fri, 03 Oct 2014 18:34:08 GMT Location: http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=www.gvisit.com&channel=&drid=&output=html Server: Apache Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=113 | clean |
http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=www.gvisit.com&channel=&drid=&output=html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://dp.g.doubleclick.net/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://dp.g.doubleclick.net//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
http://txbra.org//www.google.com/ | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=txbra.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://txbra.org/
Result: txbra.org is not infected or malware details are not published yet.
Result: txbra.org is not infected or malware details are not published yet.