Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=advertisement.domej.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://advertisement.domej.com/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: leonardclay.com
Result:
GET / HTTP/1.1
Host: leonardclay.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: leonardclay.com
Referer: http://www.google.com/search?q=leonardclay.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: leonardclay.com
Referer: http://www.google.com/search?q=leonardclay.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://advertisement.domej.com/ | HTTP/1.1 302 Found Connection: close Date: Sun, 21 Sep 2014 17:59:29 GMT Location: http://superpupermarket.com/ Server: Apache/2.2.21 (Unix) DAV/2 mod_ssl/2.2.21 OpenSSL/1.0.0c PHP/5.3.8 mod_apreq2-20090110/2.7.1 mod_perl/2.0.5 Perl/v5.10.1 Content-Length: 0 Content-Type: text/html; charset=windows-1251 X-Powered-By: PHP/5.3.8 | clean |
http://superpupermarket.com/ | HTTP/1.1 302 Found Connection: close Date: Sun, 21 Sep 2014 17:59:30 GMT Location: http://tominga.net/?code=ipmetm Server: Apache/2.2.21 (Unix) DAV/2 mod_ssl/2.2.21 OpenSSL/1.0.0c PHP/5.3.8 mod_apreq2-20090110/2.7.1 mod_perl/2.0.5 Perl/v5.10.1 Content-Length: 0 Content-Type: text/html; charset=windows-1251 X-Powered-By: PHP/5.3.8 | malicious |
http://tominga.net/?code=ipmetm | HTTP/1.1 302 Found Connection: close Date: Sun, 21 Sep 2014 17:59:30 GMT Location: http://tominga.net/?hash=04kfnq Server: nginx/1.4.3 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.5.1-1~dotdeb.1 X-Robots-Tag: noindex, nofollow, none, noarchive | clean |
http://tominga.net/?hash=04kfnq | HTTP/1.1 302 Found Connection: close Date: Sun, 21 Sep 2014 17:59:31 GMT Location: http://spinullki.com/rabotimne_ru/main.php?s=35526&tds_hash=04kfnq&security_hash=4702470188ea34a9976980120ec34e2b Server: nginx/1.4.3 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.5.1-1~dotdeb.1 X-Robots-Tag: noindex, nofollow, none, noarchive | clean |
http://spinullki.com/rabotimne_ru/main.php?s=35526&tds_hash=04kfnq&security_hash=4702470188ea34a9976980120ec34e2b | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 21 Sep 2014 17:59:31 GMT Pragma: no-cache Location: http://spinullki.com/rabotimne_ru/ Server: nginx/1.4.3 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: myjob=49lqbp7a1pjbqmu683aq0anhj0; expires=Sun, 28-Sep-2014 17:59:31 GMT; Max-Age=604800; path=/; domain=spinullki.com Set-Cookie: subaccount_id=35526; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: tds_hash=04kfnq; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=.spinullki.com Set-Cookie: town_name=Vilnius; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: country_code=LT; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: country_name=%D0%9B%D0%B8%D1%82%D0%B2%D0%B0; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: lang_code=ru; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: longitude=25.3167; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: latitude=54.6833; expires=Tue, 21-Oct-2014 17:59:31 GMT; Max-Age=2592000; path=/; domain=spinullki.com Set-Cookie: hidesocial=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=spinullki.com Set-Cookie: noflash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=spinullki.com Set-Cookie: showstream=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=spinullki.com X-Powered-By: PHP/5.5.1-1~dotdeb.1 X-Robots-Tag: noindex, nofollow, none, noarchive | clean |
http://spinullki.com/rabotimne_ru/ | 404 Not Found Content-Length: 0 Content-Type: text/html | clean |
http://spinullki.com/test404page.js | 404 Not Found Content-Length: 570 Content-Type: text/html | clean |