Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: avt-portal.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 05 Sep 2014 06:20:56 GMT
Pragma: no-cache
Server: nginx/0.7.67
Vary: Accept-Encoding
Content-Type: text/html; charset=windows-1251
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=752ghkirr40pacjvr0ai0snvk5; path=/
Set-Cookie: agg_needless=1; expires=Sat, 06-Sep-2014 06:20:56 GMT
X-Powered-By: PHP/5.2.6-1+lenny16
GET / HTTP/1.1
Host: avt-portal.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 05 Sep 2014 06:20:56 GMT
Pragma: no-cache
Server: nginx/0.7.67
Vary: Accept-Encoding
Content-Type: text/html; charset=windows-1251
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=752ghkirr40pacjvr0ai0snvk5; path=/
Set-Cookie: agg_needless=1; expires=Sat, 06-Sep-2014 06:20:56 GMT
X-Powered-By: PHP/5.2.6-1+lenny16
Second query (visit from search engine):
GET / HTTP/1.1
Host: avt-portal.ru
Referer: http://www.google.com/search?q=avt-portal.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: avt-portal.ru
Referer: http://www.google.com/search?q=avt-portal.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://avt-portal.ru/ | 200 OK Content-Length: 26120 Content-Type: text/html | clean |
http://avt-portal.ru/includes/jquery/jquery.js | 200 OK Content-Length: 85925 Content-Type: application/x-javascript | clean |
http://avt-portal.ru/core/js/common.js | 200 OK Content-Length: 381 Content-Type: application/x-javascript | clean |
http://avt-portal.ru/templates/avto/js/qslider.js | 200 OK Content-Length: 7434 Content-Type: application/x-javascript | clean |
http://avt-portal.ru/templates/avto/js/tabs.js | 200 OK Content-Length: 411 Content-Type: application/x-javascript | clean |
http://lazonia.ru/slider/banner/slider.php | 200 OK Content-Length: 7038 Content-Type: text/html | clean |
http://lazonia.ru/slider/longway.php | 200 OK Content-Length: 162 Content-Type: text/html | clean |
http://lazonia.ru/test404page.js | 404 Not Found Content-Length: 5422 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.10.1/jquery.min.js | 200 OK Content-Length: 93057 Content-Type: text/javascript | clean |
http://lazonia.ru/js/functions.js | 200 OK Content-Length: 1278 Content-Type: application/x-javascript | clean |
http://lazonia.ru/js/editor/jquery.sceditor.bbcode.min.js | 200 OK Content-Length: 68087 Content-Type: application/x-javascript | clean |
http://lazonia.ru/ | 200 OK Content-Length: 5676 Content-Type: text/html | clean |
http://lazonia.ru/songs | 200 OK Content-Length: 4586 Content-Type: text/html | clean |
http://lazonia.ru/artists | 200 OK Content-Length: 4597 Content-Type: text/html | clean |
http://lazonia.ru/news | 200 OK Content-Length: 4644 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=avt-portal.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://avt-portal.ru/
Result: avt-portal.ru is not infected or malware details are not published yet.
Result: avt-portal.ru is not infected or malware details are not published yet.