Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=chirkova.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: chirkova.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Connection: close
Date: Sun, 14 Dec 2014 07:40:09 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Length: 3923
Content-Type: text/html; charset=windows-1251
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 14 Dec 2014 07:40:09 GMT
Set-Cookie: PHPSESSID=703210734ee9383cd3fb9f8bee481a0a; path=/
...3923 bytes of data.
GET / HTTP/1.1
Host: chirkova.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Connection: close
Date: Sun, 14 Dec 2014 07:40:09 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Length: 3923
Content-Type: text/html; charset=windows-1251
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 14 Dec 2014 07:40:09 GMT
Set-Cookie: PHPSESSID=703210734ee9383cd3fb9f8bee481a0a; path=/
...3923 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: chirkova.ru
Referer: http://www.google.com/search?q=chirkova.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: chirkova.ru
Referer: http://www.google.com/search?q=chirkova.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://chirkova.ru/ | 200 OK Content-Length: 3923 Content-Type: text/html | clean |
http://rterminal.ru/it/pages/k7g8yzqm.php?id=3678226 | 200 OK Content-Length: 1 Content-Type: text/html | clean |
http://rterminal.ru/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sun, 14 Dec 2014 07:40:10 GMT Location: http://www.rterminal.ru Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0 Content-Length: 360 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.rterminal.ru/ | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 14 Dec 2014 07:40:10 GMT Pragma: no-cache Location: http://www.rterminal.ru/ru Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=855ich0u61thcvg5gmtm4l67t4; path=/ | clean |
http://www.rterminal.ru/ru | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 14 Dec 2014 07:40:10 GMT Location: http://www.rterminal.ru/ru/ Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0 Content-Length: 392 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.rterminal.ru/ru/ | 200 OK Content-Length: 20469 Content-Type: text/html | clean |
https://web.redhelper.ru/service/main.js?c=rterminal | 200 OK Content-Length: 2032 Content-Type: application/x-javascript | clean |
http://rterminal.ru/?page=28 | HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 14 Dec 2014 07:40:11 GMT Pragma: no-cache Location: http://rterminal.ru/ru Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=03shp254p5qvt3bo386o9p89j0; path=/ | clean |
http://rterminal.ru/ru | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 14 Dec 2014 07:40:11 GMT Location: http://rterminal.ru/ru/ Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0 Content-Length: 384 Content-Type: text/html; charset=iso-8859-1 | clean |
http://rterminal.ru/ru/ | 200 OK Content-Length: 20425 Content-Type: text/html | clean |
http://rterminal.ru/ru/?page=28 | 200 OK Content-Length: 18916 Content-Type: text/html | clean |
http://rterminal.ru/ru/?newscat=1 | 200 OK Content-Length: 26394 Content-Type: text/html | clean |
http://rterminal.ru/ru/?pgl=1 | 200 OK Content-Length: 20417 Content-Type: text/html | clean |
http://rterminal.ru/file/presentation/ | 200 OK Content-Length: 1902 Content-Type: text/html | clean |
http://rterminal.ru/ru/?page=9 | 200 OK Content-Length: 22681 Content-Type: text/html | clean |
http://rterminal.ru/ru/js/mobilymap.js | 200 OK Content-Length: 6433 Content-Type: application/javascript | clean |
http://rterminal.ru/ru/?page=18 | 200 OK Content-Length: 34607 Content-Type: text/html | clean |
http://rterminal.ru/ru/?page=21 | 200 OK Content-Length: 20157 Content-Type: text/html | clean |
http://rterminal.ru/ru/ifiles/docs/zayavka_na_konsultirovanie.doc | 200 OK Content-Length: 32256 Content-Type: application/msword | clean |
http://rterminal.ru/ru/ifiles/docs/zayavka_na_provedenie_tamozhennogo_oformlenia.doc | 200 OK Content-Length: 34816 Content-Type: application/msword | clean |