Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.bazza.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.bazza.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Fri, 30 Jan 2015 12:07:27 GMT Location: http://web-redirect.ru/?web Server: nginx/1.2.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Set-Cookie: _cutt_caches_images=1422619647; expires=Sat, 31-Jan-2015 12:07:27 GMT; path=/ X-Powered-By: PHP/5.3.23 | malicious |
URL: http://web-redirect.ru/?web (imitation of visitor from search engine) GET /?web HTTP/1.1 Host: web-redirect.ru Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Fri, 30 Jan 2015 12:07:27 GMT Pragma: no-cache Location: http://tatkuchma.com/components/com_weblinks/2/separator.php Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Fri, 30 Jan 2015 12:07:27 GMT X-Powered-By: PHP/5.3.3 | suspicious |
URL: http://tatkuchma.com/components/com_weblinks/2/separator.php (imitation of visitor from search engine) GET /components/com_weblinks/2/separator.php HTTP/1.1 Host: tatkuchma.com Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 30 Jan 2015 12:07:27 GMT Location: http://tvoiprazdnik.by/unit/ Server: nginx/1.4.4 Content-Length: 236 Content-Type: text/html; charset=iso-8859-1 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.bazza.ru/ | 200 OK Content-Length: 26332 Content-Type: text/html | clean |
http://www.bazza.ru/media/system/js/modal.js | 200 OK Content-Length: 10588 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/media/k2/assets/js/jquery-1.5.2.min.js | 200 OK Content-Length: 85925 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/components/com_k2/js/k2.js | 200 OK Content-Length: 6400 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/modules/mod_pd_smoothgallery/tmpl/scripts/mootools.v1.11.js | 200 OK Content-Length: 158085 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var MooTools = { version: '1.11' }; function $defined(obj){ return (obj != undefined); }; function $type(obj){ if (!$defined(obj)) return false; if (obj.htmlElement) return 'element'; var type = typeof obj; if (type == 'object' && obj.nodeName){ switch(obj.nodeType){ case 1: return 'element'; case 3: return (/\S/).test(obj.nodeValue) ? 'textnode' : 'w this.toolTip.setStyle(prop[z], pos); }; }, show: function(){ if (this.options.timeout) this.timer = this.hide.delay(this.options.timeout, this); this.fireEvent('onShow', [this.toolTip]); }, hide: function(){ this.fireEvent('onHide', [this.toolTip]); } }); Tips.implement(new Events, new Options); Antivirus reports:
| ||
http://www.bazza.ru/modules/mod_pd_smoothgallery/tmpl/scripts/jd.gallery.js | 200 OK Content-Length: 26970 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/modules/mod_pd_smoothgallery/tmpl/scripts/jd.gallery.transitions.js | 200 OK Content-Length: 2182 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/modules/mod_pd_smoothgallery/tmpl/scripts/lytebox.js | 200 OK Content-Length: 39966 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/templates/jp_musician/js/moomenu.js | 200 OK Content-Length: 4895 Content-Type: application/x-javascript | clean |
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 10689 Content-Type: text/javascript | clean |
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
http://www.bazza.ru//mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 21196 Content-Type: text/html | clean |
http://counter.rambler.ru/top100.jcn?2509979 | 200 OK Content-Length: 6853 Content-Type: application/x-javascript | clean |
http://www.bazza.ru/component/comprofiler/lostpassword.html | 200 OK Content-Length: 33463 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bazza.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bazza.ru/
Result: bazza.ru is not infected or malware details are not published yet.
Result: bazza.ru is not infected or malware details are not published yet.