Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://mest100.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: mest100.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Thu, 05 Dec 2013 04:22:03 GMT Location: http://decmexico.com/includes/domit/1.php Server: nginx/1.0.13 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | malicious |
URL: http://decmexico.com/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: decmexico.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 05 Dec 2013 04:22:03 GMT Location: http://www.csra.de/includes/domit/1.php Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | malicious |
URL: http://www.csra.de/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: www.csra.de Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 05 Dec 2013 04:22:04 GMT Location: http://www.nvn.lv/media/system/images/index/all3.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | malicious |
URL: http://www.nvn.lv/media/system/images/index/all3.php (imitation of visitor from search engine) GET /media/system/images/index/all3.php HTTP/1.1 Host: www.nvn.lv Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 05 Dec 2013 04:22:04 GMT Location: http://advertcliks.net/ir/28/1405/b93280ebecf71015360fc3f5b639f116/ Server: Apache Content-Length: 0 Content-Type: text/html | malicious |
Scanned pages/files
Request | Server response | Status |
http://mest100.ru/ | 200 OK Content-Length: 73962 Content-Type: text/html | clean |
http://mest100.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://mest100.ru/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://mest100.ru/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/md_stylechanger.js | 200 OK Content-Length: 2104 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/jquery-1.5.2.min.js?v=533e567cc1a690bf | 200 OK Content-Length: 85923 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/jquery.validate.js | 200 OK Content-Length: 38307 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/additional-methods.js | 200 OK Content-Length: 18946 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/jquery.jcarousel.js | 200 OK Content-Length: 35203 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/generic.js | 200 OK Content-Length: 26123 Content-Type: application/javascript | clean |
http://mest100.ru/templates/beez5/javascript/hide.js | 200 OK Content-Length: 8145 Content-Type: application/javascript | clean |
http://api-maps.yandex.ru/1.1/?key=AEcwNlABAAAAQVgVcwIA98B0Mm4uXjc1mC3tnRaSXejNIGQAAAAAAAAAAAAKANO57YCQ9Fd7ZtoWLqLw6HXAuA==~ABZqfFABAAAA4wkPFAIAt7zFgeX_KD-_tB-SQsj4p1DVvVwAAAAAAAAAAAB70vuELG-sn-1owi5N96jFCVwZfQ==~AB2qN1EBAAAAdbYSbgQAwvgkAekwYJRR-i_1uMGXyvSaLKkAAAAAAAAAAAD3nO3KWtcLoK-sCimaGM6XXB_3Ew==&modules=pmap&wizard=constructor | 200 OK Content-Length: 6074 Content-Type: text/javascript | clean |
http://mest100.ru/about.html | 200 OK Content-Length: 31779 Content-Type: text/html | clean |
http://mest100.ru/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 10043 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mest100.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://mest100.ru/
Result: mest100.ru is not infected or malware details are not published yet.
Result: mest100.ru is not infected or malware details are not published yet.