Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: v.ht
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 05 Oct 2014 08:13:28 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; Charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
I-AM: WW2
Set-Cookie: PHPSESSID=ijftm8ce74f990efdhqfd8eii3; path=/
GET / HTTP/1.1
Host: v.ht
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 05 Oct 2014 08:13:28 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; Charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
I-AM: WW2
Set-Cookie: PHPSESSID=ijftm8ce74f990efdhqfd8eii3; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: v.ht
Referer: http://www.google.com/search?q=v.ht
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: v.ht
Referer: http://www.google.com/search?q=v.ht
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.v.ht/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 05 Oct 2014 08:13:28 GMT Pragma: no-cache Location: http://v.ht/ Server: nginx Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT I-AM: WW1 Set-Cookie: PHPSESSID=be84d2ttnltg0pmbu7u22eana4; path=/ | clean |
http://v.ht/ | 200 OK Content-Length: 5965 Content-Type: text/html | clean |
http://v.ht/js/core-1.3.js | 200 OK Content-Length: 77009 Content-Type: application/javascript | clean |
http://www.v.ht/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 08:13:29 GMT Location: http://v.ht/test404page.js Server: nginx Content-Type: text/html; charset=UTF-8 I-AM: WW1 | clean |
http://v.ht/test404page.js | 404 Not Found Content-Length: 4522 Content-Type: text/html | clean |
http://v.ht/users/login.php | 200 OK Content-Length: 4658 Content-Type: text/html | clean |
http://v.ht/users/register.php | 200 OK Content-Length: 4682 Content-Type: text/html | clean |
http://v.ht/ar.html | 200 OK Content-Length: 6605 Content-Type: text/html | clean |
http://v.ht/en.html | 200 OK Content-Length: 5965 Content-Type: text/html | clean |
http://v.ht/fr.html | 200 OK Content-Length: 5997 Content-Type: text/html | clean |
http://v.ht/report/ | 200 OK Content-Length: 4896 Content-Type: text/html | clean |
http://v.ht/ToS/en.html | 200 OK Content-Length: 8576 Content-Type: text/html | clean |
http://v.ht/ToS/../report/ | 200 OK Content-Length: 4896 Content-Type: text/html | clean |
http://v.ht/smart/ | 200 OK Content-Length: 5367 Content-Type: text/html | clean |
http://v.ht/contactus/ | 200 OK Content-Length: 4930 Content-Type: text/html | clean |
http://v.ht/advertise | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 08:13:32 GMT Location: http://v.ht/advertise/ Server: nginx Content-Length: 230 Content-Type: text/html; charset=iso-8859-1 | clean |
http://v.ht/advertise/ | 200 OK Content-Length: 5891 Content-Type: text/html | clean |
http://v.ht/mobile.html | 200 OK Content-Length: 6103 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=v.ht
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://v.ht/
Result: v.ht is not infected or malware details are not published yet.
Result: v.ht is not infected or malware details are not published yet.