Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: uhab.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 13:26:52 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny13 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Set-Cookie: fe_typo_user=7270da490d995b6b01cc2f2337eaf598; path=/
X-Powered-By: PHP/5.2.6-1+lenny13
GET / HTTP/1.1
Host: uhab.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 13:26:52 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny13 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Set-Cookie: fe_typo_user=7270da490d995b6b01cc2f2337eaf598; path=/
X-Powered-By: PHP/5.2.6-1+lenny13
Second query (visit from search engine):
GET / HTTP/1.1
Host: uhab.de
Referer: http://www.google.com/search?q=uhab.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: uhab.de
Referer: http://www.google.com/search?q=uhab.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://uhab.de/ | 200 OK Content-Length: 10663 Content-Type: text/html | clean |
http://uhab.de/typo3temp/javascript_b9328db19d.js?1303996125 | 200 OK Content-Length: 950 Content-Type: application/javascript | clean |
http://uhab.de/fileadmin/templates/scripts/jquery.tools.min.js | 200 OK Content-Length: 111896 Content-Type: application/javascript | clean |
http://uhab.de/fileadmin/templates/scripts/jquery.syncheight.js | 200 OK Content-Length: 1345 Content-Type: application/javascript | clean |
http://uhab.de/impressum.html | 200 OK Content-Length: 7283 Content-Type: text/html | clean |
http://uhab.de/kontakt.html | 200 OK Content-Length: 10310 Content-Type: text/html | clean |
http://uhab.de/t3lib/jsfunc.validateform.js?1343552274 | 200 OK Content-Length: 4272 Content-Type: application/javascript | clean |
http://uhab.de/aktuelles.html | 200 OK Content-Length: 12736 Content-Type: text/html | clean |
http://uhab.de/unternehmen/wir-ueber-uns.html | 200 OK Content-Length: 8880 Content-Type: text/html | clean |
http://uhab.de/unternehmen/typo3temp/javascript_b9328db19d.js?1303996125 | 404 Not Found Content-Length: 1659 Content-Type: text/html | clean |
http://uhab.de/test404page.js | 404 Not Found Content-Length: 1649 Content-Type: text/html | clean |
http://uhab.de/unternehmen/fileadmin/templates/scripts/jquery.tools.min.js | 404 Not Found Content-Length: 1654 Content-Type: text/html | clean |
http://uhab.de/unternehmen/fileadmin/templates/scripts/jquery.syncheight.js | 404 Not Found Content-Length: 1655 Content-Type: text/html | clean |
http://uhab.de/beratung/beratung-logistik-produktion.html | 200 OK Content-Length: 8743 Content-Type: text/html | clean |
http://uhab.de/beratung/typo3temp/javascript_b9328db19d.js?1303996125 | 404 Not Found Content-Length: 1659 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=uhab.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://uhab.de/
Result: uhab.de is not infected or malware details are not published yet.
Result: uhab.de is not infected or malware details are not published yet.