Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=caho.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://caho.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: caho.ru
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=1
Connection: close
Date: Thu, 18 Sep 2014 01:06:23 GMT
Server: nginx
Vary: Accept-Encoding
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 18 Sep 2014 01:05:59 GMT
Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211983%7C239d7f344fe94798957d0fc3fbb5644b; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211983%7C239d7f344fe94798957d0fc3fbb5644b; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_21adf78592bd024232e3d585441226c9=%7C1412211983%7C9a701eae6e14edb0a313403e4982ab6c; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/; httponly
X-Pingback: http://caho.ru/xmlrpc.php
GET / HTTP/1.1
Host: caho.ru
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=1
Connection: close
Date: Thu, 18 Sep 2014 01:06:23 GMT
Server: nginx
Vary: Accept-Encoding
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Thu, 18 Sep 2014 01:05:59 GMT
Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211983%7C239d7f344fe94798957d0fc3fbb5644b; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211983%7C239d7f344fe94798957d0fc3fbb5644b; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_21adf78592bd024232e3d585441226c9=%7C1412211983%7C9a701eae6e14edb0a313403e4982ab6c; expires=Thu, 02-Oct-2014 01:06:23 GMT; path=/; httponly
X-Pingback: http://caho.ru/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: caho.ru
Referer: http://www.google.com/search?q=caho.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: caho.ru
Referer: http://www.google.com/search?q=caho.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://caho.ru/ | 200 OK Content-Length: 144460 Content-Type: text/html | clean |
http://lite.piclens.com/current/piclens_optimized.js?ver=3.4.1 | 200 OK Content-Length: 21750 Content-Type: application/x-javascript | clean |
http://caho.ru/wp-admin | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=1 Connection: close Date: Thu, 18 Sep 2014 01:06:27 GMT Location: http://caho.ru/wp-admin/ Server: nginx Content-Length: 232 Content-Type: text/html; charset=iso-8859-1 Expires: Thu, 18 Sep 2014 01:06:03 GMT | clean |
http://caho.ru/wp-admin/ | HTTP/1.1 302 Found Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Thu, 18 Sep 2014 01:06:28 GMT Pragma: no-cache Location: http://caho.ru/wp-login.php?redirect_to=http%3A%2F%2Fcaho.ru%2Fwp-admin%2F&reauth=1 Server: nginx Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Thu, 18 Sep 2014 01:06:28 GMT Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211988%7C09096896317d7b4eadbb3aa2c7314ffb; expires=Thu, 02-Oct-2014 01:06:28 GMT; path=/wp-content/plugins; httponly Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211988%7C09096896317d7b4eadbb3aa2c7314ffb; expires=Thu, 02-Oct-2014 01:06:28 GMT; path=/wp-admin; httponly Set-Cookie: wordpress_logged_in_21adf78592bd024232e3d585441226c9=%7C1412211988%7C1c40dcaa2e866b00480961bf4f96a3f2; expires=Thu, 02-Oct-2014 01:06:28 GMT; path=/; httponly | clean |
http://caho.ru/wp-login.php?redirect_to=http%3a%2f%2fcaho.ru%2fwp-admin%2f&reauth=1 | 200 OK Content-Length: 2060 Content-Type: text/html | clean |
http://caho.ru/wp-login.php?action=lostpassword | 200 OK Content-Length: 1684 Content-Type: text/html | clean |
http://caho.ru/wp-login.php | 200 OK Content-Length: 2060 Content-Type: text/html | clean |
http://caho.ru/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://caho.ru/news | 404 Not Found Content-Length: 321 Content-Type: text/html | clean |
http://caho.ru/sitemap.xml | 200 OK Content-Length: 46397 Content-Type: application/xml | clean |
http://caho.ru/?p=105 | 200 OK Content-Length: 300273 Content-Type: text/html | clean |
http://caho.ru/?cat=11 | 200 OK Content-Length: 142049 Content-Type: text/html | clean |
http://caho.ru/?feed=rss2&p=105 | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=1 Connection: close Date: Thu, 18 Sep 2014 01:06:32 GMT ETag: "99b889a9cd748e8b4eca0eb3758d138d" Location: http://caho.ru/?feed=rss2&p=105 Server: nginx Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html Expires: Thu, 18 Sep 2014 01:06:08 GMT Last-Modified: GMT Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211992%7C9f57bb009406d8165fdb57ef29b907f7; expires=Thu, 02-Oct-2014 01:06:32 GMT; path=/wp-content/plugins; httponly Set-Cookie: wordpress_21adf78592bd024232e3d585441226c9=%7C1412211992%7C9f57bb009406d8165fdb57ef29b907f7; expires=Thu, 02-Oct-2014 01:06:32 GMT; path=/wp-admin; httponly Set-Cookie: wordpress_logged_in_21adf78592bd024232e3d585441226c9=%7C1412211992%7C621e0f65a754303b3ff9e1fb90175739; expires=Thu, 02-Oct-2014 01:06:32 GMT; path=/; httponly X-Pingback: http://caho.ru/xmlrpc.php | clean |
http://caho.ru/?feed=rss2&p=105 | 200 OK Content-Length: 1990 Content-Type: text/xml | clean |
http://caho.ru/?p=104 | 200 OK Content-Length: 300273 Content-Type: text/html | clean |
http://caho.ru/?p=97 | 200 OK Content-Length: 303328 Content-Type: text/html | clean |
http://caho.ru/?p=315 | 200 OK Content-Length: 300273 Content-Type: text/html | clean |
http://caho.ru/?p=275 | 200 OK Content-Length: 301413 Content-Type: text/html | clean |