Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 16bar.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 03 Mar 2015 14:03:10 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA"
Set-Cookie: PHPSESSID=cj4g1hirivt8lucijs084565g3; path=/; domain=16bar.ru
Set-Cookie: BITRIX_SM_SALE_UID=75394; expires=Fri, 26-Feb-2016 14:03:10 GMT; path=/; domain=16bar.ru
X-Frame-Options: SAMEORIGIN
X-Powered-CMS: Bitrix Site Manager (4912ab68a2066d2cc55566fdeb1587c7)
GET / HTTP/1.1
Host: 16bar.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 03 Mar 2015 14:03:10 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA"
Set-Cookie: PHPSESSID=cj4g1hirivt8lucijs084565g3; path=/; domain=16bar.ru
Set-Cookie: BITRIX_SM_SALE_UID=75394; expires=Fri, 26-Feb-2016 14:03:10 GMT; path=/; domain=16bar.ru
X-Frame-Options: SAMEORIGIN
X-Powered-CMS: Bitrix Site Manager (4912ab68a2066d2cc55566fdeb1587c7)
Second query (visit from search engine):
GET / HTTP/1.1
Host: 16bar.ru
Referer: http://www.google.com/search?q=16bar.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 16bar.ru
Referer: http://www.google.com/search?q=16bar.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://16bar.ru/ | 200 OK Content-Length: 53661 Content-Type: text/html | clean |
http://16bar.ru/bitrix/js/main/core/core.js?1339667604 | 200 OK Content-Length: 57305 Content-Type: application/javascript | clean |
http://16bar.ru/bitrix/js/main/core/core_ajax.js?1339667604 | 200 OK Content-Length: 25338 Content-Type: application/javascript | clean |
http://16bar.ru/bitrix/js/main/session.js?1339667604 | 200 OK Content-Length: 3157 Content-Type: application/javascript | clean |
http://16bar.ru/bitrix/js/main/core/core_window.js?1339667604 | 200 OK Content-Length: 78654 Content-Type: application/javascript | clean |
http://16bar.ru//code.jivosite.com/script/widget/3695/ | 404 Not Found Content-Length: 28749 Content-Type: text/html | clean |
http://16bar.ru/design/jquery.js?1339667606 | 200 OK Content-Length: 91669 Content-Type: application/javascript | clean |
http://16bar.ru/design/script.js?1341072253 | 200 OK Content-Length: 1513 Content-Type: application/javascript | clean |
http://16bar.ru/bitrix/components/bitrix/search.title/script.js?1339667587 | 200 OK Content-Length: 8611 Content-Type: application/javascript | clean |
http://16bar.ru/bitrix/templates/.default/components/bitrix/search.title/search/script.js?1339667585 | 200 OK Content-Length: 8513 Content-Type: application/javascript | clean |
http://16bar.ru/about/ | 200 OK Content-Length: 29609 Content-Type: text/html | clean |
http://16bar.ru/oplata-i-dostavka/ | 200 OK Content-Length: 32974 Content-Type: text/html | clean |
http://16bar.ru/contacts/ | 200 OK Content-Length: 32358 Content-Type: text/html | clean |
http://16bar.ru/otzyvy/ | 200 OK Content-Length: 31227 Content-Type: text/html | clean |
http://16bar.ru/oplata-i-dostavka/pomoshch-pokupatelyu/index.php | 200 OK Content-Length: 30419 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=16bar.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://16bar.ru/
Result: 16bar.ru is not infected or malware details are not published yet.
Result: 16bar.ru is not infected or malware details are not published yet.