Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=missvictoria.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://missvictoria.ru/ | 200 OK Content-Length: 60925 Content-Type: text/html | clean |
http://missvictoria.ru/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://missvictoria.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://odnaknopka.ru/wp/ok2.utf8.js | 200 OK Content-Length: 6155 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function NewOdnaknopka2() {
this.domain=location.href+'/'; this.domain=this.domain.substr(this.domain.indexOf('://')+3); this.domain=this.domain.substr(0,this.domain.indexOf('/')); this.location=false; this.wpurl=false; this.wptitle=false; this.selection=function() { var sel; if (window.getSelection) sel=window.getSelection(); else if (document.selection) sel=document.selection.createRange(); else sel=''; if (sel.text) sel=sel.text; } } odnaknopka2=new NewOdnaknopka2(); function okbm(url,title) { odnaknopka2.wp(url,title); odnaknopka2.init(); } Antivirus reports:
| ||
http://gotarget.su/gen/9b24181f | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 09:59:23 GMT Location: http://partnerki-runeta.ru/category/partnerskie-programmy-s-oplatoj-za-kliki/ Server: nginx Content-Length: 285 Content-Type: text/html; charset=iso-8859-1 | clean |
http://partnerki-runeta.ru/category/partnerskie-programmy-s-oplatoj-za-kliki/ | 200 OK Content-Length: 47788 Content-Type: text/html | clean |
http://partnerki-runeta.ru//yandex.st/share/share.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=172800, private, must-revalidate Connection: close Date: Fri, 29 Aug 2014 09:59:24 GMT Pragma: no-cache Location: http://partnerki-runeta.ru/yandex.st/share/share.js/ Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://partnerki-runeta.ru/xmlrpc.php | clean |
http://partnerki-runeta.ru/yandex.st/share/share.js/ | 404 Not Found Content-Length: 21371 Content-Type: text/html | clean |
http://partnerki-runeta.ru/ | 200 OK Content-Length: 37345 Content-Type: text/html | clean |
http://partnerki-runeta.ru/chto-takoe-partnerskie-programmy/ | 200 OK Content-Length: 32381 Content-Type: text/html | clean |
http://partnerki-runeta.ru/wp-content/plugins/akismet/_inc/form.js?ver=3.0.2 | 200 OK Content-Length: 700 Content-Type: application/x-javascript | clean |
http://partnerki-runeta.ru/wp-includes/js/comment-reply.min.js?ver=3.9.2 | 200 OK Content-Length: 757 Content-Type: application/x-javascript | clean |
http://partnerki-runeta.ru/tools/ | 200 OK Content-Length: 23741 Content-Type: text/html | clean |
http://partnerki-runeta.ru/sitemap/ | 200 OK Content-Length: 36525 Content-Type: text/html | clean |
http://partnerki-runeta.ru/kontakty/ | 200 OK Content-Length: 37797 Content-Type: text/html | clean |
http://partnerki-runeta.ru/category/partnerskie-programmy-s-oplatoi-za-deistviya/ | 200 OK Content-Length: 47847 Content-Type: text/html | clean |
http://partnerki-runeta.ru/category/partnerskie-programmy-s-oplatoj-za-prosmotry/ | 200 OK Content-Length: 46319 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: missvictoria.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Aug 2014 09:59:22 GMT
Server: nginx/1.6.0
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://missvictoria.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: missvictoria.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Aug 2014 09:59:22 GMT
Server: nginx/1.6.0
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://missvictoria.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: missvictoria.ru
Referer: http://www.google.com/search?q=missvictoria.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: missvictoria.ru
Referer: http://www.google.com/search?q=missvictoria.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.