Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ksp-vrn.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 01:51:14 GMT
Pragma: no-cache
Server: nginx/1.5.7
Content-Type: text/html; charset=windows-1251
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=a282b9276dff3290cd8bccb63976f726; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: ksp-vrn.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 01:51:14 GMT
Pragma: no-cache
Server: nginx/1.5.7
Content-Type: text/html; charset=windows-1251
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=a282b9276dff3290cd8bccb63976f726; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: ksp-vrn.ru
Referer: http://www.google.com/search?q=ksp-vrn.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ksp-vrn.ru
Referer: http://www.google.com/search?q=ksp-vrn.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ksp-vrn.ru/ | 200 OK Content-Length: 23179 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.7.1.min.js | 200 OK Content-Length: 93868 Content-Type: application/x-javascript | clean |
http://ksp-vrn.ru/js/jquery.lightbox-0.5.js | 200 OK Content-Length: 20004 Content-Type: application/javascript | clean |
http://ksp-vrn.ru/js/easyTooltip.js | 200 OK Content-Length: 1817 Content-Type: application/javascript | clean |
http://ksp-vrn.ru/js/page.js | 200 OK Content-Length: 3124 Content-Type: application/javascript | clean |
http://ksp-vrn.ru/index | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Mon, 12 Jan 2015 01:51:15 GMT Pragma: no-cache Server: nginx/1.5.7 Vary: negotiate Content-Location: index.php Content-Type: text/html; charset=windows-1251 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=244ccd5fc390eb8c2ee77a0c10bd73e2; path=/ TCN: choice X-Powered-By: PHP/5.2.17 | clean |
http://ksp-vrn.ru/index.php | 200 OK Content-Length: 23179 Content-Type: text/html | clean |
http://ksp-vrn.ru/news | 200 OK Content-Length: 21449 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo | 200 OK Content-Length: 16095 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo/spravka | 200 OK Content-Length: 21114 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo/ | 200 OK Content-Length: 16095 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo/info_kadri | 200 OK Content-Length: 16747 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo/svedeniya_budzhet | 200 OK Content-Length: 14684 Content-Type: text/html | clean |
http://ksp-vrn.ru/o_kspvo/torgi | 200 OK Content-Length: 16823 Content-Type: text/html | clean |
http://ksp-vrn.ru/ksp | 200 OK Content-Length: 19329 Content-Type: text/html | clean |
http://ksp-vrn.ru/ksp/structura | 200 OK Content-Length: 17420 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ksp-vrn.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ksp-vrn.ru/
Result: ksp-vrn.ru is not infected or malware details are not published yet.
Result: ksp-vrn.ru is not infected or malware details are not published yet.