Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.ivlan.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.ivlan.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Wed, 10 Sep 2014 05:06:21 GMT Location: http://tinyurl.com/bslq4t8 Server: nginx/1.4.4 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.27-pl0-gentoo | malicious |
URL: http://tinyurl.com/bslq4t8 (imitation of visitor from search engine) GET /bslq4t8 HTTP/1.1 Host: tinyurl.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 05:06:22 GMT Location: http://humbertech.com/includes/domit/xml_domits_rss.php Server: TinyURL/1.6 Content-Length: 0 Content-Type: text/html Set-Cookie: tinyUUID=40fdc5aaa0634e9e0be2bc0e; expires=Thu, 10-Sep-2015 05:06:29 GMT; path=/; domain=.tinyurl.com X-Tiny: cache 0.0098171234130859 | malicious |
Scanned pages/files
Request | Server response | Status |
http://www.ivlan.ru/ | 200 OK Content-Length: 44282 Content-Type: text/html | clean |
http://www.ivlan.ru/components/com_proofreader/js/proofreader.js | 200 OK Content-Length: 4212 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/components/com_proofreader/js/xajax.js | 200 OK Content-Length: 16712 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 22076 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/templates/rt_affinity_j15/js/rokfonts.js | 200 OK Content-Length: 982 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/templates/rt_affinity_j15/js/rokdate.js | 200 OK Content-Length: 1079 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/templates/rt_affinity_j15/js/rokutils.js | 200 OK Content-Length: 2233 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/templates/rt_affinity_j15/js/rokutils.inputs.js | 200 OK Content-Length: 2491 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/templates/rt_affinity_j15/js/roksortable.js | 200 OK Content-Length: 8477 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/modules/mod_rokstories/tmpl/js/rokstories.js | 200 OK Content-Length: 4914 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/components/com_jcomments/js/jcomments-v2.0.js | 200 OK Content-Length: 26433 Content-Type: application/x-javascript | clean |
http://www.ivlan.ru/components/com_jcomments/libraries/joomlatune/ajax.js | 200 OK Content-Length: 3978 Content-Type: application/x-javascript | clean |
http://tinyurl.com/nz3ehwl | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 05:06:29 GMT Location: http://www.arcom-ivi.de/templates/system/css/off.js Server: TinyURL/1.6 Content-Length: 0 Content-Type: text/html Set-Cookie: tinyUUID=40fdc5a465764e9e0be2da41; expires=Thu, 10-Sep-2015 05:06:29 GMT; path=/; domain=.tinyurl.com X-Powered-By: PHP/5.4.27 X-Tiny: cache 0.012367963790894 | malicious |
http://www.arcom-ivi.de/templates/system/css/off.js | 404 Not Found Content-Length: 225 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ivlan.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ivlan.ru/
Result: ivlan.ru is not infected or malware details are not published yet.
Result: ivlan.ru is not infected or malware details are not published yet.