Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cefei.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Apr 2014 20:46:11 GMT
Pragma: no-cache
Server: nginx/0.7.67
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA"
Set-Cookie: PHPSESSID=meolr5htacqnb2n3b1963g2k43; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_GUEST_ID=101362; expires=Wed, 22-Apr-2015 20:46:10 GMT; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_LAST_VISIT=28.04.2014+00%3A46%3A10; expires=Wed, 22-Apr-2015 20:46:10 GMT; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_SALE_UID=833730; expires=Wed, 22-Apr-2015 20:46:11 GMT; path=/; domain=cefei.ru
X-Powered-By: PHP/5.3.3-7+squeeze15
X-Powered-CMS: Bitrix Site Manager (a615ac58a91ceb09623460f45be46276)
GET / HTTP/1.1
Host: cefei.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Apr 2014 20:46:11 GMT
Pragma: no-cache
Server: nginx/0.7.67
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
P3P: policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA"
Set-Cookie: PHPSESSID=meolr5htacqnb2n3b1963g2k43; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_GUEST_ID=101362; expires=Wed, 22-Apr-2015 20:46:10 GMT; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_LAST_VISIT=28.04.2014+00%3A46%3A10; expires=Wed, 22-Apr-2015 20:46:10 GMT; path=/; domain=cefei.ru
Set-Cookie: BITRIX_SM_SALE_UID=833730; expires=Wed, 22-Apr-2015 20:46:11 GMT; path=/; domain=cefei.ru
X-Powered-By: PHP/5.3.3-7+squeeze15
X-Powered-CMS: Bitrix Site Manager (a615ac58a91ceb09623460f45be46276)
Second query (visit from search engine):
GET / HTTP/1.1
Host: cefei.ru
Referer: http://www.google.com/search?q=cefei.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cefei.ru
Referer: http://www.google.com/search?q=cefei.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://cefei.ru/ | 200 OK Content-Length: 56996 Content-Type: text/html | clean |
http://cefei.ru/bitrix/cache/js/sl/cefei_sale/template_0964d5950c2f23f992ef321445730eba/template_0964d5950c2f23f992ef321445730eba_1e0be360af6e43b17294ae837b03ee68.js?1379431383 | 200 OK Content-Length: 267 Content-Type: application/x-javascript | clean |
http://cefei.ru/bitrix/cache/js/sl/cefei_sale/kernel/kernel.js?1379527173 | 200 OK Content-Length: 301184 Content-Type: application/x-javascript | clean |
http://cefei.ru/bitrix/templates/cefei_sale/overlib.js | 200 OK Content-Length: 50734 Content-Type: application/x-javascript | clean |
http://cefei.ru/index.php | 200 OK Content-Length: 55900 Content-Type: text/html | clean |
http://cefei.ru/prod/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://cefei.ru/test404page.js | 200 OK Content-Length: 41068 Content-Type: text/html | clean |
http://cefei.ru/plants/ | 200 OK Content-Length: 13458 Content-Type: text/html | clean |
http://cefei.ru/bitrix/templates/market/js/jquery-1.8.3.min.js | 200 OK Content-Length: 93637 Content-Type: application/x-javascript | clean |
http://cefei.ru/bitrix/templates/market/js/adm_scripts.js | 200 OK Content-Length: 1088 Content-Type: application/x-javascript | clean |
http://cefei.ru/vse_dlya_sada/ | 200 OK Content-Length: 13434 Content-Type: text/html | clean |
http://cefei.ru/aksessuary_dlya_floristiki/ | 200 OK Content-Length: 12805 Content-Type: text/html | clean |
http://cefei.ru/aksessuary_dlya_floristiki/izdeliya_iz_stekla/ | 200 OK Content-Length: 12187 Content-Type: text/html | clean |
http://cefei.ru/aksessuary_dlya_floristiki/izdeliya_iz_farfora_i_keramiki/ | 200 OK Content-Length: 12187 Content-Type: text/html | clean |
http://cefei.ru/aksessuary_dlya_floristiki/pletenye_izdeliya_i_korziny/ | 200 OK Content-Length: 12187 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cefei.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cefei.ru/
Result: cefei.ru is not infected or malware details are not published yet.
Result: cefei.ru is not infected or malware details are not published yet.