Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xnxxx.bz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xnxxx.bz/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://xnxxx.bz/ | 200 OK Content-Length: 43790 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: phimsex.biz <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <link rel="shortcut icon" href="http://www.xnxxx.bz/images/favicon.ico" /> <title>XNXXX, XNXXX.COM, XNXX, XXNX, WWW.XNXX.COM, XNXX VIDEO</title ...[4280 bytes skipped]... | ||
http://www.google.com/jsapi | 200 OK Content-Length: 24552 Content-Type: text/javascript | clean |
http://www.xnxxx.bz/js/rotator.js | 200 OK Content-Length: 946 Content-Type: application/javascript | clean |
http://www.xnxxx.bz/js/swfobject.js | 200 OK Content-Length: 6881 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/236683.js | 200 OK Content-Length: 1823 Content-Type: application/javascript | clean |
http://ads.adxpansion.com/public/js/showads.php?zone_id=102454&ver=1 | 200 OK Content-Length: 205 Content-Type: text/javascript | clean |
http://adspaces.ero-advertising.com/adspace/236686.js | 200 OK Content-Length: 1815 Content-Type: application/javascript | clean |
http://ads.adxpansion.com/public/js/showads.php?zone_id=102456&ver=1 | 200 OK Content-Length: 205 Content-Type: text/javascript | clean |
http://ads.juicyads.com/jsclients/jac.js | 200 OK Content-Length: 91344 Content-Type: application/x-javascript | clean |
http://adspaces.ero-advertising.com/adspace/236688.js | 200 OK Content-Length: 3836 Content-Type: application/javascript | clean |
http://xnxxx.bz/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xnxxx.bz
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 15 Sep 2014 13:30:29 GMT
Pragma: no-cache
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_perl/2.0.6 Perl/v5.10.1
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=0a5eb0b9d29f68de333bfd594c077d38; path=/
X-Powered-By: PHP/5.3.28
GET / HTTP/1.1
Host: xnxxx.bz
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 15 Sep 2014 13:30:29 GMT
Pragma: no-cache
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_perl/2.0.6 Perl/v5.10.1
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=0a5eb0b9d29f68de333bfd594c077d38; path=/
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: xnxxx.bz
Referer: http://www.google.com/search?q=xnxxx.bz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xnxxx.bz
Referer: http://www.google.com/search?q=xnxxx.bz
Result:
The result is similar to the first query. There are no suspicious redirects found.