Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=drugvokrug-telefon-lg.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://drugvokrug-telefon-lg.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: instoresandall.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sat, 05 Apr 2014 06:48:05 GMT
Pragma: no-cache
Age: 0
Server: Microsoft-IIS/7.5
Content-Length: 286
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
...286 bytes of data.
GET / HTTP/1.1
Host: instoresandall.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sat, 05 Apr 2014 06:48:05 GMT
Pragma: no-cache
Age: 0
Server: Microsoft-IIS/7.5
Content-Length: 286
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
...286 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: instoresandall.com
Referer: http://www.google.com/search?q=instoresandall.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: instoresandall.com
Referer: http://www.google.com/search?q=instoresandall.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://drugvokrug-telefon-lg.ru/ | 200 OK Content-Length: 4385 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/go.php?url=СкаÑаÑÑ | HTTP/1.1 302 Found Connection: close Date: Wed, 27 Aug 2014 05:11:20 GMT Location: http://4glooge-paly.ru/e/13842 Server: nginx lowprotect Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.4-14+deb7u9 | clean |
http://4glooge-paly.ru/e/13842 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 27 Aug 2014 05:11:20 GMT Pragma: no-cache Location: http://4glooge-paly.ru/m/7wnPkYftlKSwmGI3QgB1afB25HR Server: nginx Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: phpsid=3uu9t3ppehlftir4hp2vhvs7p3; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.4 | clean |
http://4glooge-paly.ru/m/7wnpkyftlkswmgi3qgb1afb25hr | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 27 Aug 2014 05:11:21 GMT Pragma: no-cache Location: /e/2 Server: nginx Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: phpsid=hsu3cn1tbaqae0tb3gclrlhmq3; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.4 | clean |
http://4glooge-paly.ru/e/2 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 27 Aug 2014 05:11:21 GMT Pragma: no-cache Location: http://retoq.com/l/3m7k8hDLFZca4WtrycUfcceOlpI Server: nginx Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: phpsid=2d6t2dnfr8d3bd2dji5p8b6v24; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.4 | malicious |
http://retoq.com/l/3m7k8hdlfzca4wtrycufcceolpi | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 27 Aug 2014 05:11:21 GMT Pragma: no-cache Location: /e/2 Server: nginx Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: phpsid=o6u0ftv0b0rq998cqp331fktf2; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.4 | clean |
http://retoq.com/e/2 | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 27 Aug 2014 05:11:22 GMT Pragma: no-cache Location: http://retoq.com/l/AX2x12ZZnO43QSF3xKDd1N0mbD6 Server: nginx Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: phpsid=22vo70rhdb5ac7pf6jmb308ic7; path=/ X-Powered-By: PHP/5.3.10-1ubuntu3.4 | clean |
http://retoq.com/test404page.js | 404 Not Found Content-Length: 13 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a100.php | 200 OK Content-Length: 3741 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a175.php | 200 OK Content-Length: 3776 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a190.php | 200 OK Content-Length: 3760 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a230.php | 200 OK Content-Length: 3713 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a258.php | 200 OK Content-Length: 3755 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a290.php | 200 OK Content-Length: 3723 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/a399.php | 200 OK Content-Length: 3713 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/bl20e.php | 200 OK Content-Length: 3724 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/bl40.php | 200 OK Content-Length: 3709 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/gb110.php | 200 OK Content-Length: 3719 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/GC900.php | 200 OK Content-Length: 3725 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/gd330.php | 200 OK Content-Length: 3781 Content-Type: text/html | clean |
http://drugvokrug-telefon-lg.ru/gd510.php | 200 OK Content-Length: 3760 Content-Type: text/html | clean |