Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://bash.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: bash.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 04 Sep 2014 19:23:17 GMT Pragma: no-cache Location: http://web-redirect.ru/?web Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Thu, 04 Sep 2014 19:23:17 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: _cutt_caches_images=1409858597; expires=Fri, 05-Sep-2014 19:23:17 GMT; path=/ Set-Cookie: c0814e89a38d0dafe8dbbe303f422bae=sk6fmjbkq3l2crb7f7ufc77o76; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.13 | malicious |
URL: http://web-redirect.ru/?web (imitation of visitor from search engine) GET /?web HTTP/1.1 Host: web-redirect.ru Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Thu, 04 Sep 2014 19:23:21 GMT Pragma: no-cache Location: http://room36.ru/components/com_weblinks/2/separator.php Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Thu, 04 Sep 2014 19:23:21 GMT X-Powered-By: PHP/5.3.3 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://bash.ru/ | 200 OK Content-Length: 55423 Content-Type: text/html | clean |
http://api-maps.yandex.ru/1.1/index.xml?key=AIKQpEoBAAAAjbyhDAIADeU8DYGIxGLDvKkjjpiZQtyeF54AAAAAAAAAAADxniGKr8IGJ_MNhHxwWvF1GKQ9nw==&wizard=constructor | 200 OK Content-Length: 5375 Content-Type: text/javascript | clean |
http://bash.ru/media/system/js/caption.js | 200 OK Content-Length: 2150 Content-Type: application/javascript | clean |
http://bash.ru/js-global/FancyZoom.js | 200 OK Content-Length: 23035 Content-Type: application/javascript | clean |
http://bash.ru/js-global/FancyZoomHTML.js | 200 OK Content-Length: 11965 Content-Type: application/javascript | clean |
http://informer.gismeteo.ru/flash/fcode.js | 200 OK Content-Length: 637 Content-Type: application/x-javascript | clean |
http://counter.rambler.ru/top100.jcn?1823810 | 200 OK Content-Length: 6853 Content-Type: application/x-javascript | clean |
http://bash.ru//mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 228 Content-Type: text/html | clean |
http://bash.ru/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://www.bash.ru/clickheat/js/clickheat.js | 200 OK Content-Length: 6085 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bash.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bash.ru/
Result: bash.ru is not infected or malware details are not published yet.
Result: bash.ru is not infected or malware details are not published yet.