Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=2u6.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://2u6.ru/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 2u6.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 28 Apr 2014 02:25:19 GMT
Pragma: no-cache
Server: nginx/1.4.2
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=unke627mkagbpfr57ovbpl2fq6; path=/; domain=.cbimoty.ru
Set-Cookie: stream=1; expires=Tue, 29-Apr-2014 02:25:19 GMT; path=/; domain=.cbimoty.ru
X-Powered-By: PHP/5.4.4-14+deb7u8
GET / HTTP/1.1
Host: 2u6.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 28 Apr 2014 02:25:19 GMT
Pragma: no-cache
Server: nginx/1.4.2
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=unke627mkagbpfr57ovbpl2fq6; path=/; domain=.cbimoty.ru
Set-Cookie: stream=1; expires=Tue, 29-Apr-2014 02:25:19 GMT; path=/; domain=.cbimoty.ru
X-Powered-By: PHP/5.4.4-14+deb7u8
Second query (visit from search engine):
GET / HTTP/1.1
Host: 2u6.ru
Referer: http://www.google.com/search?q=2u6.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 2u6.ru
Referer: http://www.google.com/search?q=2u6.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://2u6.ru/ | 200 OK Content-Length: 34808 Content-Type: text/html | clean |
http://2u6.ru/js/Core.js | 200 OK Content-Length: 1806 Content-Type: application/x-javascript | clean |
http://2u6.ru/js/jquery-1.4.2.min.js | 200 OK Content-Length: 72174 Content-Type: application/x-javascript | clean |
http://2u6.ru/js/content.js?v=6.3.2 | 200 OK Content-Length: 8555 Content-Type: application/x-javascript | clean |
http://2u6.ru/registration | 200 OK Content-Length: 14539 Content-Type: text/html | clean |
http://2u6.ru/js/cache/bbe18aa1f41ff408376c827ad9a86115.js | 200 OK Content-Length: 21101 Content-Type: application/x-javascript | clean |
http://2u6.ru/js/cache/registration-6.3.2.js | 200 OK Content-Length: 40192 Content-Type: application/x-javascript | clean |
http://2u6.ru/authenticate | 200 OK Content-Length: 15029 Content-Type: text/html | clean |
http://2u6.ru/index/contact | 200 OK Content-Length: 13765 Content-Type: text/html | clean |
http://2u6.ru/index/ | 200 OK Content-Length: 34808 Content-Type: text/html | clean |
http://2u6.ru/search?q=%D0%9D%D0%BE%D0%B2%D0%B8%D0%BD%D0%BA%D0%B8 | 200 OK Content-Length: 33096 Content-Type: text/html | clean |
http://2u6.ru/search?q=VA+-+%D0%A1%D0%B0%D0%BC%D1%8B%D0%B5+%D0%BB%D1%83%D1%87%D1%88%D0%B8%D0%B5+%D0%BD%D0%BE%D0%B2%D0%B8%D0%BD%D0%BA%D0%B8+%D1%80%D0%B0%D0%B4%D0%B8%D0%BE%D1%81%D1%82%D0%B0%D0%BD%D1%86%D0%B8%D0%B9+2+%5B2010%2C+Pop%2C+MP3%5D&id=80267 | 200 OK Content-Length: 33766 Content-Type: text/html | clean |
http://2u6.ru/search?q=VA+-+%D0%A1%D0%B0%D0%BC%D1%8B%D0%B5+%D0%9B%D1%83%D1%87%D1%88%D0%B8%D0%B5+%D0%9D%D0%BE%D0%B2%D0%B8%D0%BD%D0%BA%D0%B8+%D0%A0%D0%B0%D0%B4%D0%B8%D0%BE%D1%81%D1%82%D0%B0%D0%BD%D1%86%D0%B8%D0%B9+%5B2010%2C+Pop%2C+Dance%2C+MP3%5D&id=80496 | 200 OK Content-Length: 32849 Content-Type: text/html | clean |
http://2u6.ru/search?q=%D0%A5%D1%80%D0%B0%D0%BD%D0%B8%D1%82%D0%B5%D0%BB%D1%8C+%D0%A0%D0%B5%D0%BA%D0%B8&id=285870 | 200 OK Content-Length: 31982 Content-Type: text/html | clean |
http://2u6.ru/search?q=%D0%98%D0%BD%D1%81%D1%82%D1%80%D1%83%D0%BA%D1%86%D0%B8%D1%8F+%D1%86%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D0%BE%D0%B3%D0%BE+%D1%84%D0%BE%D1%82%D0%BE%D0%B0%D0%BF%D0%BF%D0%B0%D1%80%D0%B0%D1%82%D0%B0+Nikon+Coolpix+S5100&id=304027 | 200 OK Content-Length: 33573 Content-Type: text/html | clean |