Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://avtokifa.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: avtokifa.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Fri, 04 Jul 2014 12:19:10 GMT Location: http://alfsystem.com.my/includes/domit/1.php Server: Apache Content-Length: 0 Content-Type: text/html; charset=windows-1251 Expires: Fri, 04 Jul 2014 12:19:10 GMT | malicious |
URL: http://alfsystem.com.my/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: alfsystem.com.my Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 04 Jul 2014 12:19:10 GMT Location: http://www.csra.de/includes/domit/1.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.23 | malicious |
URL: http://www.csra.de/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: www.csra.de Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 04 Jul 2014 12:19:11 GMT Location: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.30 | malicious |
URL: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php (imitation of visitor from search engine) GET /components/com_user/views/login/tmpl/1/all3.php HTTP/1.1 Host: jbtconsultinggroup.com Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 04 Jul 2014 12:19:11 GMT Location: http://google.ru Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | malicious |
Scanned pages/files
Request | Server response | Status |
http://avtokifa.ru/ | 200 OK Content-Length: 26146 Content-Type: text/html | clean |
http://avtokifa.ru/media/system/js/caption.js | 200 OK Content-Length: 2800 Content-Type: application/x-javascript | clean |
http://avtokifa.ru/templates/ja_kyanite_ii/js/ja.script.js | 200 OK Content-Length: 7757 Content-Type: application/x-javascript | clean |
http://avtokifa.ru/templates/ja_kyanite_ii/js/ja.ddmod.js | 200 OK Content-Length: 17025 Content-Type: application/x-javascript | clean |
http://avtokifa.ru/templates/ja_kyanite_ii/js/menu/mega.js | 200 OK Content-Length: 2690 Content-Type: application/x-javascript | clean |
http://avtokifa.ru//mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 23435 Content-Type: text/html | clean |
http://avtokifa.ru/index.php | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=0 Connection: close Date: Fri, 04 Jul 2014 12:19:13 GMT Location: http://avtokifa.ru/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=windows-1251 Expires: Fri, 04 Jul 2014 12:19:13 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: a4bf362d653dd69979b263e3fe44028c=btbhrcd3kivt16rvqoo529eq46; path=/ | clean |
http://avtokifa.ru/test404page.js | HTTP/1.1 404 Not Found Cache-Control: max-age=0 Connection: close Date: Fri, 04 Jul 2014 12:19:13 GMT Location: http://avtokifa.ru/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=windows-1251 Expires: Fri, 04 Jul 2014 12:19:13 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: a4bf362d653dd69979b263e3fe44028c=2f3frjqif8iqmgh4o5c9k9dlt2; path=/ | clean |
http://avtokifa.ru/delivery.html | 200 OK Content-Length: 27182 Content-Type: text/html | clean |
http://avtokifa.ru/contacts.html | 200 OK Content-Length: 22987 Content-Type: text/html | clean |
http://avtokifa.ru/2011112227/ford/ford.html | 200 OK Content-Length: 22341 Content-Type: text/html | clean |
http://avtokifa.ru/ford-focus-ii/ff2group.html | 200 OK Content-Length: 26430 Content-Type: text/html | clean |
http://avtokifa.ru/ford-focus-ii/ff2dvig.html | 200 OK Content-Length: 31595 Content-Type: text/html | clean |
http://avtokifa.ru/2014-04-01-07-21-29.html | 200 OK Content-Length: 22378 Content-Type: text/html | clean |
http://avtokifa.ru/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/themes/default&file[0]=theme.js&subdir[1]=/js&file[1]=sleight.js | 200 OK Content-Length: 7794 Content-Type: text/javascript | clean |
http://avtokifa.ru/ford-focus-ii-restail/ff2rgroup.html | 200 OK Content-Length: 26795 Content-Type: text/html | clean |
http://avtokifa.ru/2011112228/kia/kia.html | 200 OK Content-Length: 22047 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=avtokifa.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://avtokifa.ru/
Result: avtokifa.ru is not infected or malware details are not published yet.
Result: avtokifa.ru is not infected or malware details are not published yet.