Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=infotumba.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://infotumba.ru/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: infotumba.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 26 Feb 2015 12:09:18 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=391vikouqgugatdij4p1deqel1; path=/
Set-Cookie: jblang=ru; expires=Mon, 14-Aug-2017 12:09:18 GMT; path=/
X-Powered-By: PHP/5.3.3-7+squeeze19
GET / HTTP/1.1
Host: infotumba.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 26 Feb 2015 12:09:18 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=391vikouqgugatdij4p1deqel1; path=/
Set-Cookie: jblang=ru; expires=Mon, 14-Aug-2017 12:09:18 GMT; path=/
X-Powered-By: PHP/5.3.3-7+squeeze19
Second query (visit from search engine):
GET / HTTP/1.1
Host: infotumba.ru
Referer: http://www.google.com/search?q=infotumba.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: infotumba.ru
Referer: http://www.google.com/search?q=infotumba.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://infotumba.ru/ | 200 OK Content-Length: 51140 Content-Type: text/html | clean |
http://infotumba.ru/images/main.js | 200 OK Content-Length: 26943 Content-Type: application/x-javascript | clean |
http://informer.gismeteo.ru/html/js/showtlist_new.js | 200 OK Content-Length: 4660 Content-Type: application/x-javascript | clean |
http://informer.gismeteo.ru/html/js/ldata_new.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://informer.gismeteo.ru/html/2.php?tnumber=1&city0=5110%D0%A0%D0%BE%D1%81%D1%82%D0%BE%D0%B2-%D0%BD%D0%B0-%D0%94%D0%BE%D0%BD%D1%83&codepg=utf-8&par=4&inflang=rus&domain=ru&vieinf=1&p=1&w=1&tblstl=gmtbl&tdttlstl=gmtdttl&tdtext=gmtdtext&new_scheme=1 | 200 OK Content-Length: 284 Content-Type: text/html | clean |
http://informer.gismeteo.ru/test404page.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://infotumba.ru/images/viewer.js | 200 OK Content-Length: 4757 Content-Type: application/x-javascript | clean |