Attacked url: http://aconal.se/uterum.htm
Attack type: SERP-hijacking (see http://ikyon.com/attack-types/ for description)
Attack detected Wed, 04 Nov 2015 01:05:28 +0100

Visitors with referer are redirected to http://outlet.monclernpiumini.it/

HTTP traffic without referer:
HTTP headers sent:
HEAD / HTTP/1.1
Host: aconal.se
Connection: Close

HTTP headers recieved:
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 8285
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDQSDQCCBQ=ICAKHJIAINFLHKECEFCKCCBO; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 Nov 2015 00:05:33 GMT
Connection: close


HTTP traffic with referer:
HTTP headers sent:
HEAD / HTTP/1.1
Host: aconal.se
Referer: http://www.google.com/search?q=aconal.se
Connection: Close

HTTP headers recieved:
HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 154
Content-Type: text/html
Location: http://outlet.monclernpiumini.it/
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDQSDQCCBQ=HCAKHJIAKPDLHAHAAFNALFHC; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 Nov 2015 00:05:32 GMT
Connection: close

aconal.se is on 80.244.64.172
ASN for 80.244.64.172: 0
Abusix contact information: abuse@t3.se (information only)
80.244.64.172 corresponds with umeagalan-se.webb2.kontrollpanel.se
Abuse.net does not have any reliable address for umeagalan-se.webb2.kontrollpanel.se
Found address in whois: abuse@t3.se