Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=forum.tupitsa.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://forum.tupitsa.net/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: forum.tupitsa.net
Result:
HTTP/1.1 200 OK
Cache-Control: private, no-cache="set-cookie"
Connection: close
Date: Wed, 30 Jul 2014 08:47:52 GMT
Pragma: no-cache
Server: nginx/1.4.4
Content-Type: text/html; charset=UTF-8
Expires: 0
Set-Cookie: phpbb3_qtvnw_u=1; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
Set-Cookie: phpbb3_qtvnw_k=; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
Set-Cookie: phpbb3_qtvnw_sid=991cba108c56382baec0edaf99c90a3d; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
X-Powered-By: PHP/5.2.17-pl0-gentoo
GET / HTTP/1.1
Host: forum.tupitsa.net
Result:
HTTP/1.1 200 OK
Cache-Control: private, no-cache="set-cookie"
Connection: close
Date: Wed, 30 Jul 2014 08:47:52 GMT
Pragma: no-cache
Server: nginx/1.4.4
Content-Type: text/html; charset=UTF-8
Expires: 0
Set-Cookie: phpbb3_qtvnw_u=1; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
Set-Cookie: phpbb3_qtvnw_k=; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
Set-Cookie: phpbb3_qtvnw_sid=991cba108c56382baec0edaf99c90a3d; expires=Thu, 30-Jul-2015 08:47:52 GMT; path=/; domain=tupitsa.net; HttpOnly
X-Powered-By: PHP/5.2.17-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: forum.tupitsa.net
Referer: http://www.google.com/search?q=forum.tupitsa.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: forum.tupitsa.net
Referer: http://www.google.com/search?q=forum.tupitsa.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://forum.tupitsa.net/ | 200 OK Content-Length: 16203 Content-Type: text/html | clean |
http://forum.tupitsa.net/./styles/1impression/template/styleswitcher.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/./styles/1impression/template/forum_fn.js | 200 OK Content-Length: 4607 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/./index.php?sid=991cba108c56382baec0edaf99c90a3d | 200 OK Content-Length: 16203 Content-Type: text/html | clean |
http://forum.tupitsa.net/././styles/1impression/template/styleswitcher.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/././styles/1impression/template/forum_fn.js | 200 OK Content-Length: 4607 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/././index.php?sid=991cba108c56382baec0edaf99c90a3d | 200 OK Content-Length: 16203 Content-Type: text/html | clean |
http://forum.tupitsa.net/./././styles/1impression/template/styleswitcher.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/./././styles/1impression/template/forum_fn.js | 200 OK Content-Length: 4607 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/./././index.php?sid=991cba108c56382baec0edaf99c90a3d | 200 OK Content-Length: 16203 Content-Type: text/html | clean |
http://forum.tupitsa.net/././././styles/1impression/template/styleswitcher.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/././././styles/1impression/template/forum_fn.js | 200 OK Content-Length: 4607 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/././././index.php?sid=991cba108c56382baec0edaf99c90a3d | 200 OK Content-Length: 16203 Content-Type: text/html | clean |
http://forum.tupitsa.net/./././././styles/1impression/template/styleswitcher.js | 200 OK Content-Length: 2528 Content-Type: application/x-javascript | clean |
http://forum.tupitsa.net/./././././styles/1impression/template/forum_fn.js | 200 OK Content-Length: 4607 Content-Type: application/x-javascript | clean |