Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: avtozapiski.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 22 Jan 2015 09:49:41 GMT
Server: nginx/0.9.6
Content-Type: text/html; charset=UTF-8
X-Pingback: http://avtozapiski.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17-0.dotdeb.0
GET / HTTP/1.1
Host: avtozapiski.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 22 Jan 2015 09:49:41 GMT
Server: nginx/0.9.6
Content-Type: text/html; charset=UTF-8
X-Pingback: http://avtozapiski.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17-0.dotdeb.0
Second query (visit from search engine):
GET / HTTP/1.1
Host: avtozapiski.ru
Referer: http://www.google.com/search?q=avtozapiski.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: avtozapiski.ru
Referer: http://www.google.com/search?q=avtozapiski.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://avtozapiski.ru/ | 200 OK Content-Length: 58696 Content-Type: text/html | clean |
http://avtozapiski.ru/wp-content/plugins/ferdinand-wordbook/common/prototype.js | 200 OK Content-Length: 126133 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/plugins/ferdinand-wordbook/common/scriptaculous.js?load=effects | 200 OK Content-Length: 2654 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/plugins/ferdinand-wordbook/lightview/js/lightview.js | 200 OK Content-Length: 29061 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/plugins/ferdinand-wordbook/prototip/js/prototip.js | 200 OK Content-Length: 9190 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-includes/js/jquery/jquery.js | 200 OK Content-Length: 93658 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/themes/sight-wordpress-theme-updated/sight/js/jquery.cycle.all.min.js | 200 OK Content-Length: 31032 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/themes/sight-wordpress-theme-updated/sight/js/jquery.cookie.js | 200 OK Content-Length: 4246 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/themes/sight-wordpress-theme-updated/sight/js/script.js | 200 OK Content-Length: 5233 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-includes/js/swfobject.js | 200 OK Content-Length: 10231 Content-Type: application/x-javascript | clean |
http://static.widgets.elifantiev.ru/widgets/widgets.js | 404 Not Found Content-Length: 375 Content-Type: text/html | clean |
http://static.widgets.elifantiev.ru/test404page.js | 404 Not Found Content-Length: 375 Content-Type: text/html | clean |
http://connect.facebook.net/ru_RU/all.js | 200 OK Content-Length: 161925 Content-Type: application/x-javascript | clean |
http://avtozapiski.ru/wp-content/plugins/wp-banners-lite/wpbanners_show.php?id=2&cid=a_c81e728d9d4c2f636f067f89cc14862c | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://avtozapiski.ru/wp-includes/js/thickbox/thickbox.js | 200 OK Content-Length: 12417 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=avtozapiski.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://avtozapiski.ru/
Result: avtozapiski.ru is not infected or malware details are not published yet.
Result: avtozapiski.ru is not infected or malware details are not published yet.