Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fly-it.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://fly-it.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://fly-it.ru/ | 200 OK Content-Length: 39256 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery(document).ready(function(){ jQuery("img").not("").lazyload({ effect : "fadeIn" }); }); Antivirus reports:
| ||
http://fly-it.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://fly-it.ru/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://fly-it.ru/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
http://fly-it.ru/media/system/js/modal.js | 200 OK Content-Length: 9732 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/jcemediabox/js/jcemediabox.js?version=1111 | 200 OK Content-Length: 56532 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/js/jquery-1.8.3.min.js | 200 OK Content-Length: 93636 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/js/jquery.noconflict.js | 200 OK Content-Length: 930 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/bootstrap/js/bootstrap.js | 200 OK Content-Length: 61962 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/js/script.js | 200 OK Content-Length: 5625 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/js/menu.js | 200 OK Content-Length: 2850 Content-Type: application/javascript | clean |
http://fly-it.ru/plugins/system/t3/base/js/responsive.js | 200 OK Content-Length: 3061 Content-Type: application/javascript | clean |
http://fly-it.ru/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: application/javascript | clean |
http://fly-it.ru/modules/mod_news_pro_gk4/interface/scripts/engine.js | 200 OK Content-Length: 8034 Content-Type: application/javascript | clean |
http://fly-it.ru/templates/portal/js/template.js | 200 OK Content-Length: 7793 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: fly-it.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Mon, 06 Oct 2014 03:05:35 GMT
Pragma: no-cache
Server: Apache/2.2.17 (Unix) PHP/5.3.11
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 85612e2ba16887acf156fba2a8300b8d=mi8d9vqbiheqvmpfsct2s3u5i7; path=/
X-Powered-By: PHP/5.3.11
GET / HTTP/1.1
Host: fly-it.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Mon, 06 Oct 2014 03:05:35 GMT
Pragma: no-cache
Server: Apache/2.2.17 (Unix) PHP/5.3.11
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 85612e2ba16887acf156fba2a8300b8d=mi8d9vqbiheqvmpfsct2s3u5i7; path=/
X-Powered-By: PHP/5.3.11
Second query (visit from search engine):
GET / HTTP/1.1
Host: fly-it.ru
Referer: http://www.google.com/search?q=fly-it.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: fly-it.ru
Referer: http://www.google.com/search?q=fly-it.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.