Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: agent.ez3.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Feb 2015 05:45:19 GMT
Server: nginx
Content-Type: text/html; charset=utf-8
Set-Cookie: 7150ef4d9ef47146a4ba919060517614=c12b021d8ededf0d2b76834125ef859a; expires=Sun, 01-Mar-2015 05:45:19 GMT; path=/
Set-Cookie: vexxci1102=d41d8cd98f00b204e9800998ecf8427e; expires=Mon, 30-Mar-2015 05:45:19 GMT; path=/
Set-Cookie: vexxcg1105=cfcd208495d565ef66e7dff9f98764da; expires=Mon, 30-Mar-2015 05:45:19 GMT; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: agent.ez3.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Feb 2015 05:45:19 GMT
Server: nginx
Content-Type: text/html; charset=utf-8
Set-Cookie: 7150ef4d9ef47146a4ba919060517614=c12b021d8ededf0d2b76834125ef859a; expires=Sun, 01-Mar-2015 05:45:19 GMT; path=/
Set-Cookie: vexxci1102=d41d8cd98f00b204e9800998ecf8427e; expires=Mon, 30-Mar-2015 05:45:19 GMT; path=/
Set-Cookie: vexxcg1105=cfcd208495d565ef66e7dff9f98764da; expires=Mon, 30-Mar-2015 05:45:19 GMT; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: agent.ez3.ru
Referer: http://www.google.com/search?q=agent.ez3.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: agent.ez3.ru
Referer: http://www.google.com/search?q=agent.ez3.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://agent.ez3.ru/ | 200 OK Content-Length: 13575 Content-Type: text/html | clean |
http://agent.ez3.ru/sitemap | 200 OK Content-Length: 14990 Content-Type: text/html | clean |
http://agent.ez3.ru/test404page.js | 404 Not Found Content-Length: 3135 Content-Type: text/html | clean |
http://promotium.net/av.php?p=6&z=4 | 200 OK Content-Length: 4003 Content-Type: text/html | clean |
http://promotium.net/av.php?r=aHR0cDovL3d3dy53bXRvb2xib3gubmV0Lw==&i=28 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 28 Feb 2015 05:45:22 GMT Pragma: no-cache Location: http://www.wmtoolbox.net/ Server: nginx Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sat, 28 Feb 2015 05:45:22 GMT Access-Control-Allow-Origin: * Set-Cookie: PRMT=6caad428b3a361399d3c4a072fa0300c; path=/ X-Powered-By: PHP/5.2.14 | clean |
http://www.wmtoolbox.net/ | 200 OK Content-Length: 43840 Content-Type: text/html | clean |
http://www.wmtoolbox.net/style/jMetro/js/jquery-1.6.2.min.js | 200 OK Content-Length: 91556 Content-Type: application/javascript | clean |
http://promotium.net/style/jMetro/js/jquery-ui-1.8.16.custom.min.js | 404 Not Found Content-Length: 109 Content-Type: text/html | clean |
http://promotium.net/test404page.js | 404 Not Found Content-Length: 77 Content-Type: text/html | clean |
http://promotium.net/scripts/menu.js | 404 Not Found Content-Length: 78 Content-Type: text/html | clean |
http://promotium.net/scripts/chosen.jquery.min.js | 404 Not Found Content-Length: 91 Content-Type: text/html | clean |
http://promotium.net/SpryAssets/SpryMenuBar.js | 404 Not Found Content-Length: 88 Content-Type: text/html | clean |
http://promotium.net/scripts/noty/jquery.noty.js | 404 Not Found Content-Length: 90 Content-Type: text/html | clean |
http://promotium.net/scripts/noty/layouts/bottomRight.js | 404 Not Found Content-Length: 98 Content-Type: text/html | clean |
http://promotium.net/scripts/noty/themes/default.js | 404 Not Found Content-Length: 93 Content-Type: text/html | clean |
http://scripts.optidesk.ru/callback.js | 200 OK Content-Length: 35115 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=agent.ez3.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://agent.ez3.ru/
Result: agent.ez3.ru is not infected or malware details are not published yet.
Result: agent.ez3.ru is not infected or malware details are not published yet.