Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=farmlend-orto.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: farmlend-orto.ru
Result:
HTTP/1.1 200 OK
Cache-Control: private, must-revalidate
Connection: close
Date: Tue, 23 Sep 2014 02:18:30 GMT
Server: nginx/1.4.4
Content-Type: text/html; charset=UTF-8
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Set-Cookie: SN4d427564d9635=bjra5jjffsid6ddl3lbo2ppqh3; path=/
Set-Cookie: SN4d427564d9635=bjra5jjffsid6ddl3lbo2ppqh3; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
GET / HTTP/1.1
Host: farmlend-orto.ru
Result:
HTTP/1.1 200 OK
Cache-Control: private, must-revalidate
Connection: close
Date: Tue, 23 Sep 2014 02:18:30 GMT
Server: nginx/1.4.4
Content-Type: text/html; charset=UTF-8
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Set-Cookie: SN4d427564d9635=bjra5jjffsid6ddl3lbo2ppqh3; path=/
Set-Cookie: SN4d427564d9635=bjra5jjffsid6ddl3lbo2ppqh3; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: farmlend-orto.ru
Referer: http://www.google.com/search?q=farmlend-orto.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: farmlend-orto.ru
Referer: http://www.google.com/search?q=farmlend-orto.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://farmlend-orto.ru/ | 200 OK Content-Length: 14207 Content-Type: text/html | clean |
http://farmlend-orto.ru/js/jquery142.js | 200 OK Content-Length: 72326 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/js/main.js | 200 OK Content-Length: 3771 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/js/floaty.js | 200 OK Content-Length: 3633 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/facefiles/facebox.js | 200 OK Content-Length: 7066 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/assets/snippets/shopkeeper/js/jquery-1.4.2.min.js | 200 OK Content-Length: 72174 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/assets/snippets/shopkeeper/lang/russian-UTF8.js | 200 OK Content-Length: 854 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/assets/snippets/shopkeeper/js/shopkeeper.js | 200 OK Content-Length: 14313 Content-Type: application/x-javascript | clean |
http://farmlend-orto.ru/medicinskie-uslugi | 200 OK Content-Length: 7878 Content-Type: text/html | clean |
http://farmlend-orto.ru/catalog | 200 OK Content-Length: 13172 Content-Type: text/html | clean |
http://farmlend-orto.ru/contacts | HTTP/1.1 302 Found Cache-Control: private, must-revalidate Connection: close Date: Tue, 23 Sep 2014 02:18:34 GMT Location: http://farmlend-orto.ru/contacts/201 Server: nginx/1.4.4 Content-Length: 0 Content-Type: text/html P3P: CP="NOI NID ADMa OUR IND UNI COM NAV" Set-Cookie: SN4d427564d9635=snbt3g79o3oc4s40p7u0dd4564; path=/ Set-Cookie: SN4d427564d9635=snbt3g79o3oc4s40p7u0dd4564; path=/ X-Powered-By: PHP/5.2.17-pl0-gentoo | clean |
http://farmlend-orto.ru/contacts/201 | 200 OK Content-Length: 9531 Content-Type: text/html | clean |
http://api-maps.yandex.ru/1.1/index.xml?key=AFRbbk0BAAAA5Z5FMQIADDYaQWQwv1mcijm54HcpihIM9cQAAAAAAAAAAAA7nVan-p-7ds8djptQWxkff6JRyA== | 200 OK Content-Length: 5375 Content-Type: text/javascript | clean |
http://farmlend-orto.ru/contacts/202 | 200 OK Content-Length: 9520 Content-Type: text/html | clean |
http://farmlend-orto.ru/contacts/ | HTTP/1.1 302 Found Cache-Control: private, must-revalidate Connection: close Date: Tue, 23 Sep 2014 02:18:36 GMT Location: http://farmlend-orto.ru/contacts/201 Server: nginx/1.4.4 Content-Length: 0 Content-Type: text/html P3P: CP="NOI NID ADMa OUR IND UNI COM NAV" Set-Cookie: SN4d427564d9635=o2h9r582jn01r1as9og9llugb3; path=/ Set-Cookie: SN4d427564d9635=o2h9r582jn01r1as9og9llugb3; path=/ X-Powered-By: PHP/5.2.17-pl0-gentoo | clean |
http://farmlend-orto.ru/test404page.js | 404 Not Found Content-Length: 14201 Content-Type: text/html | clean |
http://farmlend-orto.ru/14 | 200 OK Content-Length: 20657 Content-Type: text/html | clean |