Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=amour.coca.bz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://amour.coca.bz/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://amour.coca.bz/ | 200 OK Content-Length: 45807 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: webcams.sex-ru.org <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <title>Çíàêîìñòâà Àìóð: Ìîñêâà, Ñàíêò-Ïåòåðáóðã, Ðîññèÿ, çíàêîìñòâà dating ru</title> <META http-equiv="Content-Type" content="text/html; charset=windows-1251" /> <META NAME="keywords" CONTENT="çíàêîìñòâà â ...[4399 bytes skipped]... | ||
http://amour.coca.bz/style/jquery.min.js | 200 OK Content-Length: 94840 Content-Type: application/x-javascript | clean |
http://amour.coca.bz/style/event_listeners.js | 200 OK Content-Length: 830 Content-Type: application/x-javascript | clean |
http://amour.coca.bz/style/resolution.js | 200 OK Content-Length: 1781 Content-Type: application/x-javascript | clean |
http://amour.coca.bz/style/manage.js?21122012 | 200 OK Content-Length: 22957 Content-Type: application/x-javascript | clean |
http://amour.coca.bz/style/calls.js | 200 OK Content-Length: 4394 Content-Type: application/x-javascript | clean |
http://amour.coca.bz/style/swfobject.js | 200 OK Content-Length: 10229 Content-Type: application/x-javascript | clean |
http://odnaknopka.ru/ok2.js | 200 OK Content-Length: 6105 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function NewOdnaknopka2() {
this.domain=location.href+'/'; this.domain=this.domain.substr(this.domain.indexOf('://')+3); this.domain=this.domain.substr(0,this.domain.indexOf('/')); this.location=false; this.selection=function() { var sel; if (window.getSelection) sel=window.getSelection(); else if (document.selection) sel=document.selection.createRange(); else sel=''; if (sel.text) sel=sel.text; return encodeURIComponent(sel); } th } } odnaknopka2=new NewOdnaknopka2(); odnaknopka2.init(); Antivirus reports:
| ||
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 6875 Content-Type: text/javascript | clean |
http://p83477.adskape.ru/adout.js?p=83477&t=1 | 200 OK Content-Length: 389 Content-Type: text/html | clean |
http://p83477.adskape.ru/adout.php?p=83477&t=1&sid=' + sid + ref + topfr +' | 200 OK Content-Length: 456 Content-Type: text/html | clean |
http://p83477.adskape.ru/adclick.php?id=11184&p=83477&tid=806f2a26f105dc0a6a4ee255ebec9d14&tid1=a387739c0351f589001c97f505c5ec1d&tid2=2841558&psid=0 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 14 Sep 2014 10:28:29 GMT Location: http://roulettesekret.ru/landing1/ Server: nginx/1.2.4 Content-Type: text/html Set-Cookie: click[]=11184; expires=Sun, 14-Sep-2014 20:00:00 GMT X-Powered-By: PHP/5.4.7 | clean |
http://roulettesekret.ru/landing1/ | 200 OK Content-Length: 9003 Content-Type: text/html | clean |
http://roulettesekret.ru/test404page.js | 404 Not Found Content-Length: 1734 Content-Type: text/html | clean |
http://roulettesekret.ru/ | 200 OK Content-Length: 17102 Content-Type: text/html | clean |
http://roulettesekret.ru/obygrat.php | 200 OK Content-Length: 13726 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: amour.coca.bz
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sun, 14 Sep 2014 10:28:24 GMT
Server: nginx
Content-Type: text/html
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Sun, 14 Sep 2014 10:28:24 GMT
GET / HTTP/1.1
Host: amour.coca.bz
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sun, 14 Sep 2014 10:28:24 GMT
Server: nginx
Content-Type: text/html
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Sun, 14 Sep 2014 10:28:24 GMT
Second query (visit from search engine):
GET / HTTP/1.1
Host: amour.coca.bz
Referer: http://www.google.com/search?q=amour.coca.bz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: amour.coca.bz
Referer: http://www.google.com/search?q=amour.coca.bz
Result:
The result is similar to the first query. There are no suspicious redirects found.