Author Topic: Cloaking, status code differences and ET POLICY HTTP Request to a *.tk domain  (Read 973 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: https://urlquery.net/report/c982439d-ae40-4752-97e6-cd9f968ad005
and https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=ubdns.wlmacao.tk%2F&ref_sel=GSP2&ua_sel=ff&fs=1
and http://isithacked.com/check/ubdns.wlmacao.tk%2F

error
Quote
  (var newurl) -domain.dot.tk/p/?d=UBDNS.WLMACAO.TK&i=107.170.38.188&c=1&ro=0&ref=unknown&_=1531857449096
     status: (referer=http:/XXX/web?q=puppies)saved 24164 bytes 9469da6afe1f452401d990e3f4b582cb3b530304
     info: [script] -ajax.googleapis.com/ajax/libs/jquery/1.6.4/jquery.min.js
     info: [script]- html5shiv.googlecode.com/svn/trunk/html5.js
     info: [script] -code.jquery.com/jquery-1.9.0.js
     info: [script] -ajax.googleapis.com/ajax/libs/jquery/2.0.3/jquery.min.js
     info: [script] -domain.dot.tk/js/rotatingbg.js
     info: [script] -my.freenom.com/external/jsrender.min.js
     info: [script] -my.freenom.com/includes/domains/fn-available.js
     info: [script] -code.jquery.com/ui/1.11.2/jquery-ui.js
     info: [img] -domain.dot.tk/p/../images.v2/logo.png
     info: [iframe] -domain.dot.tk/en/iframe.html
     info: [decodingLevel=0] found JavaScript
     error: line:58: SyntaxError: missing : after property id:
          error: line:58:                <tr {{if type == "SPECIAL"}} class="specials" {{/if}}>
          error: line:58: .................................^
     error: line:3: SyntaxError: missing = in XML attribute:
          error: line:3: <!DOCTYPE html PUBLIC "-/W3C/DTD XHTML 1.0 Transitional/EN" "http:/www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
          error: line:3: ...............^
     file: 9469da6afe1f452401d990e3f4b582cb3b530304: 24164 bytes

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!