Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://yxren.w24.west263.cn/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: yxren.w24.west263.cn Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 moved temporarily Cache-Control: private Date: Thu, 04 Dec 2014 09:08:00 GMT Location: http://stopnote.vhostgo.com/?host=yxren%2Ew24%2Ewest263%2Ecn&refer=http%3A%2F%2Fwww%2Egoogle%2Ecom%2Furl%3Fsa%3Dt%26rct%3Dj%26q%3Dyxren%2Ew24%2Ewest263%2Ecn%26source%3Dweb%26cd%3D1%26ved%3D0CDEQFjAG%26url%3Dhttp%3A%252F%252Fyxren%2Ew24%2Ewest263%2Ecn%252F%26ei%3DwC7yT5qCJbCCkQKtnwE%26usg%3DAFQjCNGEeYp3D7uuNLAJxMIVliLyQ9O%5FPg Server: Microsoft-IIS/6.0 Content-Length: 0 Content-Type: text/html Set-Cookie: ASPSESSIONIDCATRBRBB=CKNFMNAALNJONHFGLAMCAOPC; path=/ X-Powered-By: ASP.NET | malicious |
Scanned pages/files
Request | Server response | Status |
http://yxren.w24.west263.cn/2009/getip.asp | HTTP/1.1 302 moved temporarily Cache-Control: private Date: Thu, 04 Dec 2014 09:07:52 GMT Location: http://stopnote.vhostgo.com/?host=yxren%2Ew24%2Ewest263%2Ecn&refer= Server: Microsoft-IIS/6.0 Content-Length: 0 Content-Type: text/html Set-Cookie: ASPSESSIONIDCATRBRBB=BKNFMNAANPMHKBJPLEOFPNFN; path=/ X-Powered-By: ASP.NET | clean |
http://stopnote.vhostgo.com/?host=yxren%2ew24%2ewest263%2ecn&refer= | 200 OK Content-Length: 2311 Content-Type: text/html | clean |
http://stopnote.vhostgo.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=yxren.w24.west263.cn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://yxren.w24.west263.cn/
Result: yxren.w24.west263.cn is not infected or malware details are not published yet.
Result: yxren.w24.west263.cn is not infected or malware details are not published yet.