Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lazonia.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 05 Mar 2015 01:45:20 GMT
Server: nginx/1.6.2
Content-Type: text/html; charset=utf-8
Set-Cookie: ci_session=a%3A5%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%226da7fec2f95894645a254bcf88ea4b46%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A13%3A%2278.158.11.226%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A50%3A%22Mozilla%2F4.0+%28compatible%3B+MSIE+8.0%3B+Windows+NT+5.1%29%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1425519920%3Bs%3A9%3A%22user_data%22%3Bs%3A0%3A%22%22%3B%7Dc7463996831586996165870b1b970e98; expires=Thu, 05-Mar-2015 03:45:20 GMT; path=/
X-Powered-By: PHP/5.2.6-1+lenny16
GET / HTTP/1.1
Host: lazonia.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 05 Mar 2015 01:45:20 GMT
Server: nginx/1.6.2
Content-Type: text/html; charset=utf-8
Set-Cookie: ci_session=a%3A5%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%226da7fec2f95894645a254bcf88ea4b46%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A13%3A%2278.158.11.226%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A50%3A%22Mozilla%2F4.0+%28compatible%3B+MSIE+8.0%3B+Windows+NT+5.1%29%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1425519920%3Bs%3A9%3A%22user_data%22%3Bs%3A0%3A%22%22%3B%7Dc7463996831586996165870b1b970e98; expires=Thu, 05-Mar-2015 03:45:20 GMT; path=/
X-Powered-By: PHP/5.2.6-1+lenny16
Second query (visit from search engine):
GET / HTTP/1.1
Host: lazonia.ru
Referer: http://www.google.com/search?q=lazonia.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lazonia.ru
Referer: http://www.google.com/search?q=lazonia.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://lazonia.ru/ | 200 OK Content-Length: 11982 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.10.1/jquery.min.js | 200 OK Content-Length: 93057 Content-Type: text/javascript | clean |
http://lazonia.ru/js/editor/jquery.sceditor.bbcode.min.js | 200 OK Content-Length: 68087 Content-Type: application/javascript | clean |
http://lazonia.ru/js/functions.js | 200 OK Content-Length: 1278 Content-Type: application/javascript | clean |
http://lazonia.ru/genre/rock | 200 OK Content-Length: 17961 Content-Type: text/html | clean |
http://lazonia.ru/genre/ | 404 Not Found Content-Length: 14443 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/A | 200 OK Content-Length: 15422 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/ | 404 Not Found Content-Length: 14443 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/B | 200 OK Content-Length: 15375 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/C | 200 OK Content-Length: 15706 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/D | 200 OK Content-Length: 14735 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/E | 200 OK Content-Length: 14180 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/F | 200 OK Content-Length: 15540 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/G | 200 OK Content-Length: 13871 Content-Type: text/html | clean |
http://lazonia.ru/songsletter/H | 200 OK Content-Length: 15410 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lazonia.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://lazonia.ru/
Result: lazonia.ru is not infected or malware details are not published yet.
Result: lazonia.ru is not infected or malware details are not published yet.