Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=372.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://372.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://372.ru/ | 200 OK Content-Length: 17469 Content-Type: text/html | clean |
http://www.meteoprog.ua/informers/?id=1314321511 | 200 OK Content-Length: 3184 Content-Type: text/html | clean |
http://www.meteoprog.ua/test404page.js | 404 Not Found Content-Length: 46886 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/js/adriver/adriver.core.2.js | 200 OK Content-Length: 5236 Content-Type: application/x-javascript | clean |
http://www.meteoprog.ua/js/content_roll/adfox.asyn.code.ver3.js | 200 OK Content-Length: 3318 Content-Type: application/x-javascript | clean |
http://www.meteoprog.ua/js/content_roll/adfox.asyn.code.scroll.js | 200 OK Content-Length: 2410 Content-Type: application/x-javascript | clean |
http://www.meteoprog.ua/cache/js/bundle_5b96f45c5d4ba88b454326cba659808e.js?1391084307 | 200 OK Content-Length: 195432 Content-Type: application/x-javascript | clean |
http://www.meteoprog.ua/en/about/ | 200 OK Content-Length: 39097 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/en/catalog/Ukraine | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 01 Apr 2014 20:44:10 GMT Location: http://www.meteoprog.ua/en/catalog/Ukraine/ Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://www.meteoprog.ua/en/catalog/ukraine/ | 200 OK Content-Length: 300499 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_204" class="informer" ><!-- banner_place:before_all_notua;
banner_id: 204; banner_name:top banner UA for zabugor; banner_order:50;--><div id="top_banner" style="display:block;width:100%; min-height:89px; background: #f2f2f2; text-align:center; left: 50%; width: 728px; position: relative; margin: 0px 0px 0px -364px;" > <!-- AdRiver code START. </script> <script type="text/javascript"><!-- google_ad_client = "ca-pub-5337958802379722"; /* 728x90_Meteoprog_ua_world */ google_ad_slot = "6135672607"; google_ad_width = 728; google_ad_height = 90; //--> </script> <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script> </div></div> | ||
http://www.meteoprog.ua/en/ | 200 OK Content-Length: 108254 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/ru/uagreement/ | 200 OK Content-Length: 92331 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/ru/catalog/Ukraine | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 01 Apr 2014 20:44:16 GMT Location: http://www.meteoprog.ua/ru/catalog/Ukraine/ Server: nginx Content-Length: 178 Content-Type: text/html | clean |
http://www.meteoprog.ua/ru/catalog/ukraine/ | 200 OK Content-Length: 300492 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_204" class="informer" ><!-- banner_place:before_all_notua;
banner_id: 204; banner_name:top banner UA for zabugor; banner_order:50;--><div id="top_banner" style="display:block;width:100%; min-height:89px; background: #f2f2f2; text-align:center; left: 50%; width: 728px; position: relative; margin: 0px 0px 0px -364px;" > <!-- AdRiver code START. </script> <script type="text/javascript"><!-- google_ad_client = "ca-pub-5337958802379722"; /* 728x90_Meteoprog_ua_world */ google_ad_slot = "6135672607"; google_ad_width = 728; google_ad_height = 90; //--> </script> <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script> </div></div> | ||
http://www.meteoprog.ua/ru/ | 200 OK Content-Length: 123767 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/ru/about/ | 200 OK Content-Length: 73702 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_102" class="informer" ><!-- banner_place:footer_our_projects;
banner_id: 102; banner_name:avtobazar UA; banner_order:50;--><a rel="nofollow" class="informer" style="float:right; margin-top:13px;" href="http://auto.ria.ua/">ÐвÑобазаÑ</a> </div> | ||
http://www.meteoprog.ua/ru/weather/Kyiv/ | 200 OK Content-Length: 302032 Content-Type: text/html | suspicious |
Suspicious code found <div id="mp_banner_235" class="informer" ><!-- banner_place:right;
banner_id: 235; banner_name:mobile-popovnen; banner_order:10;--><a href="/golink/https://easypay.ua/" rel='nofollow' target='_blank'> <img src='http://www.meteoprog.ua/pictures/banners/images/meteo_banner.png' style="border:none;margin-top:10px" /> </a></div> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 372.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 01 Apr 2014 20:44:17 GMT
Server: Apache/2.2.26 (FreeBSD) PHP/5.4.26 mod_ssl/2.2.26 OpenSSL/1.0.1f
Content-Type: text/html
X-Powered-By: PHP/5.4.26
GET / HTTP/1.1
Host: 372.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 01 Apr 2014 20:44:17 GMT
Server: Apache/2.2.26 (FreeBSD) PHP/5.4.26 mod_ssl/2.2.26 OpenSSL/1.0.1f
Content-Type: text/html
X-Powered-By: PHP/5.4.26
Second query (visit from search engine):
GET / HTTP/1.1
Host: 372.ru
Referer: http://www.google.com/search?q=372.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 372.ru
Referer: http://www.google.com/search?q=372.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.