Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xpstar.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 05 Oct 2014 01:48:32 GMT
Location: http://www.xpstar.com/
Server: Apache
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
...230 bytes of data.
GET / HTTP/1.1
Host: xpstar.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 05 Oct 2014 01:48:32 GMT
Location: http://www.xpstar.com/
Server: Apache
Content-Length: 230
Content-Type: text/html; charset=iso-8859-1
...230 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: xpstar.com
Referer: http://www.google.com/search?q=xpstar.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xpstar.com
Referer: http://www.google.com/search?q=xpstar.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://xpstar.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:32 GMT Location: http://www.xpstar.com/ Server: Apache Content-Length: 230 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/ | 200 OK Content-Length: 275265 Content-Type: text/html | clean |
http://www.xpstar.com/modern-ticker/js/jquery-1.9.1.min.js | 200 OK Content-Length: 92633 Content-Type: application/x-javascript | clean |
http://xpstar.com/modern-ticker/js/jquery.modern-ticker.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:34 GMT Location: http://www.xpstar.com/modern-ticker/js/jquery.modern-ticker.min.js Server: Apache Content-Length: 274 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/modern-ticker/js/jquery.modern-ticker.min.js | 200 OK Content-Length: 6127 Content-Type: application/x-javascript | clean |
http://xpstar.com//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:35 GMT Location: http://www.xpstar.com/translate.google.com/translate_a/element.js?cb=googleTranslateElementInit/ Server: Apache Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/translate.google.com/translate_a/element.js?cb=googletranslateelementinit/ | 404 Not Found Content-Length: 1549 Content-Type: text/html | clean |
http://www.xpstar.com/test404page.js | 404 Not Found Content-Length: 1549 Content-Type: text/html | clean |
http://www.google.co.uk/jsapi | 200 OK Content-Length: 24554 Content-Type: text/javascript | clean |
http://code.jquery.com/jquery-1.8.3.min.js | 200 OK Content-Length: 93636 Content-Type: application/x-javascript | clean |
http://xpstar.com/./javascript/jquery.carouFredSel-6.1.0.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:36 GMT Location: http://www.xpstar.com/javascript/jquery.carouFredSel-6.1.0.js Server: Apache Content-Length: 269 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/javascript/jquery.caroufredsel-6.1.0.js | 200 OK Content-Length: 96683 Content-Type: application/x-javascript | clean |
http://xpstar.com/./javascript/jquery.cslider.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:36 GMT Location: http://www.xpstar.com/javascript/jquery.cslider.js Server: Apache Content-Length: 258 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/javascript/jquery.cslider.js | 200 OK Content-Length: 7160 Content-Type: application/x-javascript | clean |
http://xpstar.com/./javascript/modernizr.custom.28468.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:37 GMT Location: http://www.xpstar.com/javascript/modernizr.custom.28468.js Server: Apache Content-Length: 266 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/javascript/modernizr.custom.28468.js | 200 OK Content-Length: 7524 Content-Type: application/x-javascript | clean |
http://xpstar.com/./javascript/getTweet.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:37 GMT Location: http://www.xpstar.com/javascript/getTweet.js Server: Apache Content-Length: 252 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/javascript/gettweet.js | 200 OK Content-Length: 1830 Content-Type: application/x-javascript | clean |
http://xpstar.com/./javascript/jquery.fancybox.js?v=2.1.3 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 01:48:37 GMT Location: http://www.xpstar.com/javascript/jquery.fancybox.js?v=2.1.3 Server: Apache Content-Length: 267 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.xpstar.com/javascript/jquery.fancybox.js?v=2.1.3 | 200 OK Content-Length: 49836 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xpstar.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xpstar.com/
Result: xpstar.com is not infected or malware details are not published yet.
Result: xpstar.com is not infected or malware details are not published yet.