Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xnxxhdsex.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 10 Feb 2015 20:45:38 GMT
Location: http://www.xnxxhdsex.com/
Server: nginx
Content-Length: 233
Content-Type: text/html; charset=iso-8859-1
...233 bytes of data.
GET / HTTP/1.1
Host: xnxxhdsex.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 10 Feb 2015 20:45:38 GMT
Location: http://www.xnxxhdsex.com/
Server: nginx
Content-Length: 233
Content-Type: text/html; charset=iso-8859-1
...233 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: xnxxhdsex.com
Referer: http://www.google.com/search?q=xnxxhdsex.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xnxxhdsex.com
Referer: http://www.google.com/search?q=xnxxhdsex.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://xnxxhdsex.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 10 Feb 2015 20:45:38 GMT Location: http://www.xnxxhdsex.com/ Server: nginx Content-Length: 233 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xnxxhdsex.com/ | 200 OK Content-Length: 166073 Content-Type: text/html | clean |
http://www.xnxxhdsex.com//ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js/ | 404 Not Found Content-Length: 13482 Content-Type: text/html | clean |
http://html5shim.googlecode.com/svn/trunk/html5.js | 200 OK Content-Length: 2429 Content-Type: text/javascript | clean |
http://www.xnxxhdsex.com/templates/xnxx/assets/js/common.mini.js | 200 OK Content-Length: 702 Content-Type: application/x-javascript | clean |
http://www.xnxxhdsex.com//s7.addthis.com/js/300/addthis_widget.js/ | 404 Not Found Content-Length: 13482 Content-Type: text/html | clean |
http://www.xnxxhdsex.com/latest/ | 200 OK Content-Length: 269622 Content-Type: text/html | clean |
http://www.xnxxhdsex.com/longest/ | 200 OK Content-Length: 247861 Content-Type: text/html | clean |
http://www.xnxxhdsex.com/popular/ | 200 OK Content-Length: 261988 Content-Type: text/html | clean |
http://www.xnxxhdsex.com/ftt2/o.php?u=http://beeg.com/1044226?i=lucky7 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate Connection: close Date: Tue, 10 Feb 2015 20:45:44 GMT Pragma: no-cache Location: http://beeg.com/1044226?i=lucky7 Server: nginx Content-Length: 0 Content-Type: text/html Set-Cookie: ftt2=YTo1OntzOjI6ImlwIjtpOjEzMTg5ODA1Nzg7czoxOiJmIjtzOjE6IjAiO3M6MToicyI7czo1OiJub3JlZiI7czoxOiJ2IjthOjA6e31zOjI6ImNjIjtpOjE7fQ%3D%3D; expires=Wed, 11-Feb-2015 20:45:44 GMT; path=/; domain=.xnxxhdsex.com | clean |
http://beeg.com/1044226?i=lucky7 | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 10 Feb 2015 20:45:44 GMT Location: http://beeg.com/1044226 Server: nginx/1.6.1 Content-Length: 184 Content-Type: text/html Set-Cookie: seller_id=lucky7;domain=beeg.com;Max-Age=1800 | clean |
http://beeg.com/1044226 | 200 OK Content-Length: 27646 Content-Type: text/html | clean |
http://beeg.com//ajax.googleapis.com/ajax/libs/jquery/2.1.3/jquery.min.js/ | 404 Not Found Content-Length: 0 Content-Type: text/html | clean |
http://beeg.com/test404page.js | 404 Not Found Content-Length: 570 Content-Type: text/html | clean |
http://www.xnxxhdsex.com//staticloads.com/js/global.js?v=2015.01.31/ | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.xnxxhdsex.com//staticloads.com/js/cozy.js?v=2015.01.31/ | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.xnxxhdsex.com//staticloads.com/players/jw.5.7.1896/jwplayer.js?v=2015.01.31/ | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://www.xnxxhdsex.com//staticloads.com/js/ad-inplayer.js?v=2015.01.31/ | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xnxxhdsex.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xnxxhdsex.com/
Result: xnxxhdsex.com is not infected or malware details are not published yet.
Result: xnxxhdsex.com is not infected or malware details are not published yet.