Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: alima-star.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Thu, 16 Apr 2015 21:18:17 GMT
Pragma: no-cache
Server: nginx/1.6.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d975c039be3b574a54c3c02f4cc1044a=8dde8fcb40f0682b6ddf077862c9883e; path=/; HttpOnly
X-Powered-By: PHP/5.3.13
GET / HTTP/1.1
Host: alima-star.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Thu, 16 Apr 2015 21:18:17 GMT
Pragma: no-cache
Server: nginx/1.6.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: d975c039be3b574a54c3c02f4cc1044a=8dde8fcb40f0682b6ddf077862c9883e; path=/; HttpOnly
X-Powered-By: PHP/5.3.13
Second query (visit from search engine):
GET / HTTP/1.1
Host: alima-star.ru
Referer: http://www.google.com/search?q=alima-star.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: alima-star.ru
Referer: http://www.google.com/search?q=alima-star.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://alima-star.ru/ | 200 OK Content-Length: 22850 Content-Type: text/html | clean |
http://alima-star.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 83893 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/core.js | 200 OK Content-Length: 3813 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/mootools-more.js | 200 OK Content-Length: 236825 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/validate.js | 200 OK Content-Length: 3320 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/modal.js | 200 OK Content-Length: 9732 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/calendar.js | 200 OK Content-Length: 30313 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/system/js/calendar-setup.js | 200 OK Content-Length: 3090 Content-Type: application/x-javascript | clean |
http://alima-star.ru/media/mod_pwebcontact/js/mootools.pwebcontact.js | 200 OK Content-Length: 11856 Content-Type: application/x-javascript | clean |
http://alima-star.ru/templates/olmezan2/js/jquery.js | 200 OK Content-Length: 93894 Content-Type: application/x-javascript | clean |
http://alima-star.ru/templates/olmezan2/js/superfish.js | 200 OK Content-Length: 5035 Content-Type: application/x-javascript | clean |
http://alima-star.ru/templates/olmezan2/js/hoverIntent.js | 200 OK Content-Length: 3838 Content-Type: application/x-javascript | clean |
http://alima-star.ru/templates/olmezan2/js/nivo.slider.js | 200 OK Content-Length: 11671 Content-Type: application/x-javascript | clean |
http://alima-star.ru/templates/olmezan2/js/scroll.js | 200 OK Content-Length: 121 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=alima-star.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://alima-star.ru/
Result: alima-star.ru is not infected or malware details are not published yet.
Result: alima-star.ru is not infected or malware details are not published yet.