Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kazanka.su
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Apr 2014 21:28:11 GMT
Server: Apache/2.2.6 (Fedora)
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kazanka.su/xmlrpc.php
X-Powered-By: PHP/5.2.6
GET / HTTP/1.1
Host: kazanka.su
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Apr 2014 21:28:11 GMT
Server: Apache/2.2.6 (Fedora)
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kazanka.su/xmlrpc.php
X-Powered-By: PHP/5.2.6
Second query (visit from search engine):
GET / HTTP/1.1
Host: kazanka.su
Referer: http://www.google.com/search?q=kazanka.su
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kazanka.su
Referer: http://www.google.com/search?q=kazanka.su
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.kazanka.su/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Apr 2014 21:28:10 GMT Location: http://kazanka.su/ Server: Apache/2.2.6 (Fedora) Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://kazanka.su/xmlrpc.php X-Powered-By: PHP/5.2.6 | clean |
http://kazanka.su/ | 200 OK Content-Length: 10713 Content-Type: text/html | clean |
http://kazanka.su/wp-content/themes/viewport/js/jquery-1.2.1.pack.js | 200 OK Content-Length: 27147 Content-Type: application/x-javascript | clean |
http://kazanka.su/wp-content/themes/viewport/js/jquery-easing.1.2.pack.js | 200 OK Content-Length: 3429 Content-Type: application/x-javascript | clean |
http://kazanka.su/wp-content/themes/viewport/js/jquery-easing-compatibility.1.2.pack.js | 200 OK Content-Length: 1567 Content-Type: application/x-javascript | clean |
http://kazanka.su/wp-content/themes/viewport/js/coda-slider.1.1.1.js | 200 OK Content-Length: 6089 Content-Type: application/x-javascript | clean |
http://www.kazanka.su//mc.yandex.ru/metrika/watch.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 18 Apr 2014 21:28:14 GMT Pragma: no-cache Location: http://kazanka.su/mc.yandex.ru/metrika/watch.js/ Server: Apache/2.2.6 (Fedora) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://kazanka.su/xmlrpc.php X-Powered-By: PHP/5.2.6 | clean |
http://kazanka.su/mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 6185 Content-Type: text/html | clean |
http://kazanka.su//mc.yandex.ru/metrika/watch.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 18 Apr 2014 21:28:14 GMT Pragma: no-cache Location: http://kazanka.su/mc.yandex.ru/metrika/watch.js/ Server: Apache/2.2.6 (Fedora) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://kazanka.su/xmlrpc.php X-Powered-By: PHP/5.2.6 | clean |
http://kazanka.su/test404page.js | 404 Not Found Content-Length: 529 Content-Type: text/html | clean |
http://www.kazanka.su//mc.yandex.ru/metrika/watch_visor.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 18 Apr 2014 21:28:15 GMT Pragma: no-cache Location: http://kazanka.su/mc.yandex.ru/metrika/watch_visor.js/ Server: Apache/2.2.6 (Fedora) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://kazanka.su/xmlrpc.php X-Powered-By: PHP/5.2.6 | clean |
http://kazanka.su/mc.yandex.ru/metrika/watch_visor.js/ | 404 Not Found Content-Length: 6185 Content-Type: text/html | clean |
http://kazanka.su//mc.yandex.ru/metrika/watch_visor.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 18 Apr 2014 21:28:16 GMT Pragma: no-cache Location: http://kazanka.su/mc.yandex.ru/metrika/watch_visor.js/ Server: Apache/2.2.6 (Fedora) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://kazanka.su/xmlrpc.php X-Powered-By: PHP/5.2.6 | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kazanka.su
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://kazanka.su/
Result: kazanka.su is not infected or malware details are not published yet.
Result: kazanka.su is not infected or malware details are not published yet.