Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xs14.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xs14.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 21 Sep 2014 11:29:44 GMT
Pragma: no-cache
Server: Microsoft-IIS/7.5
Content-Length: 5645
Content-Type: text/html; charset=utf-8
Expires: -1
P3p: CP="CAO PSA OUR"
Set-Cookie: SessionID=9f42f3bb-1da1-4920-8921-4a8c6752ea35; path=/
Set-Cookie: VisitorID=c62b5085-54dc-43a7-9720-b63f6053d8ac&Exp=9/21/2017 4:29:45 AM; expires=Thu, 21-Sep-2017 11:29:45 GMT; path=/
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
...5645 bytes of data.
GET / HTTP/1.1
Host: xs14.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 21 Sep 2014 11:29:44 GMT
Pragma: no-cache
Server: Microsoft-IIS/7.5
Content-Length: 5645
Content-Type: text/html; charset=utf-8
Expires: -1
P3p: CP="CAO PSA OUR"
Set-Cookie: SessionID=9f42f3bb-1da1-4920-8921-4a8c6752ea35; path=/
Set-Cookie: VisitorID=c62b5085-54dc-43a7-9720-b63f6053d8ac&Exp=9/21/2017 4:29:45 AM; expires=Thu, 21-Sep-2017 11:29:45 GMT; path=/
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
...5645 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: xs14.com
Referer: http://www.google.com/search?q=xs14.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xs14.com
Referer: http://www.google.com/search?q=xs14.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://xs14.com/ | 200 OK Content-Length: 5645 Content-Type: text/html | clean |
http://code.jquery.com/jquery-latest.min.js | 200 OK Content-Length: 95786 Content-Type: application/x-javascript | clean |
http://xs14.com/js/standard.js?rte=1&tm=2&dn=xs14.com&tid=1020 | 200 OK Content-Length: 1297 Content-Type: text/javascript | clean |
http://xs14.com/static/cash-advance?slt=21&slr=1&lpt=0&yt= | HTTP/1.1 302 Found Cache-Control: private Date: Sun, 21 Sep 2014 11:29:46 GMT Location: /click Server: Microsoft-IIS/7.5 Content-Length: 123 Content-Type: text/html; charset=utf-8 P3p: CP="CAO PSA OUR" Set-Cookie: SessionID=c6537f4d-7f86-4575-823b-8dc121b9b9ab; path=/ Set-Cookie: VisitorID=094a6e3c-297b-4794-8447-c882ac2720ed&Exp=9/21/2017 4:29:47 AM; expires=Thu, 21-Sep-2017 11:29:47 GMT; path=/ X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://xs14.com/click | 200 OK Content-Length: 5645 Content-Type: text/html | clean |
http://xs14.com/static/debt-consolidation?slt=21&slr=2&lpt=0&yt= | HTTP/1.1 302 Found Cache-Control: private Date: Sun, 21 Sep 2014 11:29:49 GMT Location: /click Server: Microsoft-IIS/7.5 Content-Length: 123 Content-Type: text/html; charset=utf-8 P3p: CP="CAO PSA OUR" Set-Cookie: SessionID=a5080b99-eaa0-4ade-a6e4-3e979fc60a52; path=/ Set-Cookie: VisitorID=7cf956e8-ba91-4217-adf5-f87807706b5d&Exp=9/21/2017 4:29:49 AM; expires=Thu, 21-Sep-2017 11:29:49 GMT; path=/ X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://xs14.com/test404page.js | 200 OK Content-Length: 5642 Content-Type: text/html | clean |
http://xs14.com/static/insurance?slt=21&slr=3&lpt=0&yt= | HTTP/1.1 302 Found Cache-Control: private Date: Sun, 21 Sep 2014 11:29:49 GMT Location: /click Server: Microsoft-IIS/7.5 Content-Length: 123 Content-Type: text/html; charset=utf-8 P3p: CP="CAO PSA OUR" Set-Cookie: SessionID=df2d3b9e-4c8b-467c-8eb2-9c00d5aefabb; path=/ Set-Cookie: VisitorID=0c5788d0-d523-48c2-ad5a-206214f05f44&Exp=9/21/2017 4:29:50 AM; expires=Thu, 21-Sep-2017 11:29:50 GMT; path=/ X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://xs14.com/static/free-credit-report?slt=21&slr=4&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/cell-phones?slt=21&slr=5&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/life-insurance?slt=21&slr=6&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/credit-card-application?slt=21&slr=7&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/real-estate?slt=21&slr=8&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/cheap-airfare?slt=21&slr=9&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/static/finance?slt=21&slr=10&lpt=0&yt= | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |
http://xs14.com/renewal.aspx | 500 Status read failed: Соединение ÑазоÑвано дÑÑгой ÑÑоÑоной Content-Length: 140 Content-Type: text/plain | clean |