Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: white-flag.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 17:06:32 GMT
Accept-Ranges: bytes
Accept-Ranges: bytes
Age: 0
Server: Apache/2
Content-Length: 8921
Content-Type: text/html
...8921 bytes of data.
GET / HTTP/1.1
Host: white-flag.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 17:06:32 GMT
Accept-Ranges: bytes
Accept-Ranges: bytes
Age: 0
Server: Apache/2
Content-Length: 8921
Content-Type: text/html
...8921 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: white-flag.org
Referer: http://www.google.com/search?q=white-flag.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: white-flag.org
Referer: http://www.google.com/search?q=white-flag.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://white-flag.org/ | 200 OK Content-Length: 8921 Content-Type: text/html | clean |
http://white-flag.org/projects.html | 200 OK Content-Length: 4892 Content-Type: text/html | clean |
http://white-flag.org/hzl | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 17:06:34 GMT Accept-Ranges: bytes Age: 0 Location: http://white-flag.org/hzl/ Server: Apache/2 Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 | clean |
http://white-flag.org/hzl/ | 200 OK Content-Length: 5358 Content-Type: text/html | clean |
http://white-flag.org/hzl/mp3/hzlstudioclip1.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/test404page.js | HTTP/1.1 404 Not Found Connection: close Date: Sun, 05 Oct 2014 17:06:37 GMT Accept-Ranges: bytes Accept-Ranges: bytes Age: 0 Server: Apache/2 Content-Length: 1186 Content-Type: text/html | clean |
http://white-flag.org/../index.html | 400 Bad Request Content-Length: 166 Content-Type: text/html | clean |
http://white-flag.org/hzl/mp3/hzlstudioclip2.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/hzl/mp3/hzlclip1.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/hzl/mp3/hzlclip2.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/hzl/mp3/redroom_3_11_06.mp3 | 200 OK Content-Length: 300987 Content-Type: audio/mpeg | clean |
http://white-flag.org/hzl/mp3/HZL_1_27_06.mp3 | 200 OK Content-Length: 300987 Content-Type: audio/mpeg | clean |
http://white-flag.org/hzl/mp3/HZL_JW_SHK_1_27.mp3 | 200 OK Content-Length: 300987 Content-Type: audio/mpeg | clean |
http://white-flag.org/tweeter/index.html | 200 OK Content-Length: 5074 Content-Type: text/html | clean |
http://white-flag.org/tweeter/tweeter1.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/tweeter/tweeter2.mp3 | 200 OK Content-Length: 300988 Content-Type: audio/mpeg | clean |
http://white-flag.org/index.html | 200 OK Content-Length: 8921 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=white-flag.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://white-flag.org/
Result: white-flag.org is not infected or malware details are not published yet.
Result: white-flag.org is not infected or malware details are not published yet.