Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=id-am.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 10val.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 14 Sep 2014 06:32:32 GMT
Pragma: no-cache
Server: nginx/1.2.3
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=76bMypjBEJ3gsi7sz1GkI3; expires=Sun, 14-Sep-2014 12:32:32 GMT; path=/
Set-Cookie: cook=ok; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: acc=21002; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: pss=1410676352; expires=Sun, 14-Sep-2014 16:32:32 GMT; path=/
Set-Cookie: country=LT; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: _ft=1410687152; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
X-Powered-By: PHP/5.4.6
GET / HTTP/1.1
Host: 10val.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 14 Sep 2014 06:32:32 GMT
Pragma: no-cache
Server: nginx/1.2.3
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=76bMypjBEJ3gsi7sz1GkI3; expires=Sun, 14-Sep-2014 12:32:32 GMT; path=/
Set-Cookie: cook=ok; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: acc=21002; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: pss=1410676352; expires=Sun, 14-Sep-2014 16:32:32 GMT; path=/
Set-Cookie: country=LT; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
Set-Cookie: _ft=1410687152; expires=Tue, 14-Oct-2014 06:32:32 GMT; path=/
X-Powered-By: PHP/5.4.6
Second query (visit from search engine):
GET / HTTP/1.1
Host: 10val.ru
Referer: http://www.google.com/search?q=10val.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 10val.ru
Referer: http://www.google.com/search?q=10val.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://id-am.ru/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 07 Sep 2014 17:17:23 GMT Location: http://compton-rp.ru/neww_clo/tds/master.php?i=1&q=%D1%EA%E0%F7%E0%F2%FC+%EA%E0%F8%E5%EB%FC+%F3+%F0%E5%E1%E5%ED%EA%E0+1+%E3%EE%E4+%F7%E5%EC+%EB%E5%F7%E8%F2%FC+%E1%E5%F1%EF%EB%E0%F2%ED%EE+-+%CF%F0%EE%E3%F0%E0%EC%EC%FB&v=3&host=id-am.ru Server: nginx/1.4.3 Content-Type: text/html X-Powered-By: PHP/5.4.21-1~dotdeb.1 | malicious |
http://compton-rp.ru/neww_clo/tds/master.php?i=1&q=%d1%ea%e0%f7%e0%f2%fc+%ea%e0%f8%e5%eb%fc+%f3+%f0%e5%e1%e5%ed%ea%e0+1+%e3%ee%e4+%f7%e5%ec+%eb%e5%f7%e8%f2%fc+%e1%e5%f1%ef%eb%e0%f2%ed%ee+-+%cf%f0%ee%e3%f0%e0%ec%ec%fb&v=3&host=id-am.ru | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 07 Sep 2014 17:17:24 GMT Location: http://magic-pw.ru/?books&keyword=Ñêà÷àòü êàøåëü ó ðåáåíêà 1 ãîä ÷åì ëå÷èòü áåñïëàòíî - Ïðîãðàììû Server: nginx/1.2.1 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.4.25-1~dotdeb.1 | malicious |
http://magic-pw.ru/?books&keyword=Ñêà÷àòü êàøåëü ó ðåáåíêà 1 ãîä ÷åì ëå÷èòü áåñïëàòíî - Ïðîãðàììû | HTTP/1.1 302 Moved Temporarily Cache-Control: max-age=0 Connection: close Date: Sun, 07 Sep 2014 17:17:24 GMT Pragma: no-cache Location: http://bagetitaly.ru/?aburj Server: nginx/1.4.3 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Sun, 07 Sep 2014 17:17:24 GMT X-Powered-By: PHP/5.4.21-1~dotdeb.1 | malicious |
http://bagetitaly.ru/?aburj | HTTP/1.1 302 Moved Temporarily Cache-Control: max-age=0 Connection: close Date: Sun, 07 Sep 2014 17:17:25 GMT Pragma: no-cache Location: http://stoptraff/?670d455d4b609f962c5ba287b49b5e94= Server: nginx/1.4.3 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Sun, 07 Sep 2014 17:17:24 GMT X-Powered-By: PHP/5.4.21-1~dotdeb.1 | clean |
http://stoptraff/?670d455d4b609f962c5ba287b49b5e94= | 500 Can't connect to stoptraff:80 (Bad hostname) Content-Length: 150 Content-Type: text/plain | clean |
http://stoptraff/test404page.js | 500 Can't connect to stoptraff:80 (Bad hostname) Content-Length: 150 Content-Type: text/plain | clean |