Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ikonas.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Wed, 16 Jul 2014 04:19:23 GMT
Server: nginx/1.2.0
Content-Length: 13086
Content-Type: text/html; charset=utf-8
Expires: Wed, 16 Jul 2014 04:19:23 GMT
...13086 bytes of data.
GET / HTTP/1.1
Host: ikonas.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Wed, 16 Jul 2014 04:19:23 GMT
Server: nginx/1.2.0
Content-Length: 13086
Content-Type: text/html; charset=utf-8
Expires: Wed, 16 Jul 2014 04:19:23 GMT
...13086 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ikonas.ru
Referer: http://www.google.com/search?q=ikonas.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ikonas.ru
Referer: http://www.google.com/search?q=ikonas.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ikonas.ru/ | 200 ok Content-Length: 13086 Content-Type: text/html | clean |
http://ikonas.ru/nok111.js?PHPSESSID=696b6f6e6173727567386f6060737271 | 200 ok Content-Length: 561 Content-Type: text/plain | clean |
http://ikonas.ru/test404page.js | 404 not found Content-Length: 196 Content-Type: text/html | clean |
http://ikonas.ru/koi111.js?PHPSESSID=696b6f6e6173727567286f6090737271 | 200 ok Content-Length: 292 Content-Type: text/plain | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21245 Content-Type: text/javascript | clean |
http://script.days.ru/calendar.php?advanced=1&name=0&hram=0&trop=0&images=0&relics=0&icon=0&%trapeza=1&vek=0&short=0 | HTTP/1.1 302 Found Connection: close Date: Wed, 16 Jul 2014 04:26:35 GMT Location: http://script2.pravoslavie.ru/cache/advanced=1&name=0&hram=0&trop=0&images=0&relics=0&icon=0&.ls Server: nginx Content-Length: 308 Content-Type: text/html; charset=iso-8859-1 | clean |
http://script2.pravoslavie.ru/cache/advanced=1&name=0&hram=0&trop=0&images=0&relics=0&icon=0&.ls | 200 Ok Content-Length: 1779 Content-Type: text/html | clean |
http://ikonas.ru/koi111.js?PHPSESSID=696b6f6e6173727567286f6015737271 | 200 ok Content-Length: 292 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ikonas.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ikonas.ru/
Result: ikonas.ru is not infected or malware details are not published yet.
Result: ikonas.ru is not infected or malware details are not published yet.