Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=usgci.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://usgci.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: usgci.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 16 Apr 2014 01:39:10 GMT
Location: http://www.usgci.com/
Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 339
Content-Type: text/html; charset=iso-8859-1
...339 bytes of data.
GET / HTTP/1.1
Host: usgci.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 16 Apr 2014 01:39:10 GMT
Location: http://www.usgci.com/
Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 339
Content-Type: text/html; charset=iso-8859-1
...339 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: usgci.com
Referer: http://www.google.com/search?q=usgci.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: usgci.com
Referer: http://www.google.com/search?q=usgci.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://usgci.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:10 GMT Location: http://www.usgci.com/ Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 339 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/ | 200 OK Content-Length: 83125 Content-Type: text/html | clean |
http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_imagehover.js | 200 OK Content-Length: 6571 Content-Type: application/javascript | clean |
http://usgci.com/includes/templates/pradajapan013/jscript/jscript_jquery.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:12 GMT Location: http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_jquery.js Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 397 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_jquery.js | 200 OK Content-Length: 57254 Content-Type: application/javascript | clean |
http://usgci.com/includes/templates/pradajapan013/jscript/jscript_jscroller2-1.5.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:13 GMT Location: http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_jscroller2-1.5.js Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 405 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_jscroller2-1.5.js | 200 OK Content-Length: 5321 Content-Type: application/javascript | clean |
http://usgci.com/includes/templates/pradajapan013/jscript/jscript_packed.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:14 GMT Location: http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_packed.js Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 397 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_packed.js | 200 OK Content-Length: 21854 Content-Type: application/javascript | clean |
http://usgci.com/includes/templates/pradajapan013/jscript/jscript_slider.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:15 GMT Location: http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_slider.js Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 397 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/includes/templates/pradajapan013/jscript/jscript_slider.js | 200 OK Content-Length: 1658 Content-Type: application/javascript | clean |
http://js.users.51.la/16658600.js | 200 OK Content-Length: 1980 Content-Type: application/x-javascript | clean |
http://usgci.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 16 Apr 2014 01:39:16 GMT Location: http://www.usgci.com/test404page.js Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 353 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.usgci.com/test404page.js | 404 Not Found Content-Length: 58026 Content-Type: text/html | clean |
http://www.usgci.com/login.html | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 16 Apr 2014 01:39:17 GMT Location: http://www.usgci.com/index.php?main_page=cookie_usage Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Content-Length: 0 Content-Type: text/html; charset=utf-8 Set-Cookie: cookie_test=please_accept_for_session; expires=Fri, 16-May-2014 01:39:17 GMT; Max-Age=2592000; path=/; domain=www.usgci.com X-Powered-By: PHP/5.5.10 | clean |
http://www.usgci.com/index.php?main_page=cookie_usage | 200 OK Content-Length: 56071 Content-Type: text/html | clean |
http://www.usgci.com/create_account.html | 200 OK Content-Length: 97052 Content-Type: text/html | clean |
http://www.usgci.com/shopping_cart.html | 200 OK Content-Length: 96037 Content-Type: text/html | clean |
http://www.usgci.com/includes/general.js | 200 OK Content-Length: 5842 Content-Type: application/javascript | clean |
http://www.usgci.com/products_new.html | 200 OK Content-Length: 87993 Content-Type: text/html | clean |
http://www.usgci.com/æ¯æé
é-ezp-2.html | 200 OK Content-Length: 55732 Content-Type: text/html | clean |
http://www.usgci.com/discount_coupon.html | 200 OK Content-Length: 55945 Content-Type: text/html | clean |