Scanned pages/files
Request | Server response | Status |
http://mob-xxxx.net/ | 200 OK Content-Length: 2396 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.4.4.min.js | 200 OK Content-Length: 78601 Content-Type: application/x-javascript | clean |
http://mob-xxxx.net/themes/restore1/script/main.js | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://mob-xxxx.net/themes/restore1/script/main | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://mob-xxxx.net/terms | 200 OK Content-Length: 25283 Content-Type: text/html | clean |
http://mob-xxxx.net/test404page.js | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://mob-xxxx.net/main | 200 OK Content-Length: 3762 Content-Type: text/html | clean |
http://mob-xxxx.net/subscribe | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 05 Mar 2015 19:55:30 GMT Location: http://ya.ru/ Server: nginx/1.2.1 Content-Type: text/html Set-Cookie: s=1; path=/ Set-Cookie: param_pagenewuser=http%3A%2F%2Fmob-xxxx.net%2Freturn; path=/ X-Powered-By: PHP/5.4.6-1ubuntu1.8 | clean |
http://ya.ru/ | 200 Ok Content-Length: 11319 Content-Type: text/html | clean |
http://ya.ru//yastatic.net/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 79107 Content-Type: text/html | clean |
http://ya.ru//yastatic.net/www/2.261/v12/pages-desktop/error404/_error404.ru.js/ | 404 Not Found Content-Length: 79139 Content-Type: text/html | clean |
http://ya.ru//www.yandex.ru/ | 404 Not Found Content-Length: 79075 Content-Type: text/html | clean |
http://ya.ru//maps.yandex.ru/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 05 Mar 2015 19:58:13 GMT Location: http://maps.yandex.ru Server: nginx Content-Length: 154 Content-Type: text/html | clean |
http://maps.yandex.ru/ | 200 OK Content-Length: 51397 Content-Type: text/html | suspicious |
Suspicious code found <table class="b-head-userinfo b-head-userinfo_is-bem_yes i-bem i-bem" onclick="return {'b-head-userinfo':{name:'b-head-userinfo'}}"><tr><td class="b-head-userinfo__td"></td><td class="b-head-userinfo__entry"><a class="b-link b-link_pseudo_yes" href="https://passport.yandex.ru//passport?mode=auth&msg=maps&retpath=http%3A%2F%2Fmaps.yandex.ru%2F" onmousedown="Lego.ch('maps.login.enter',this)"><span class="b-link__inner">ÐойÑи</span></a><form class="b-domik b-domik_type_popup i-bem i-hidden" action="https://passport.yandex.ru//passport?mode=auth&from=maps&twoweeks=yes&retpath=http%3A%2F%2Fmaps.yandex.ru%2F" method="post" onclick="return {'b-domik':{name:'b-domik_type_popup',title:''}}"><input name="login"><input name="passwd" type="password"><input name="twoweeks" type="checkbox" value="no"></form></td></tr></table> | ||
http://maps.yandex.ru/print/ | 200 OK Content-Length: 6814 Content-Type: text/html | clean |
http://maps.yandex.ru//yandex.st/swf/swfobject/2.2-yandex1/_swfobject.js/ | 404 Not Found Content-Length: 79332 Content-Type: text/html | clean |
http://maps.yandex.ru//yastatic.net/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 79314 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mob-xxxx.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 05 Mar 2015 19:55:28 GMT
Server: nginx/1.2.1
Content-Type: text/html
Set-Cookie: s=1; path=/
X-Powered-By: PHP/5.4.6-1ubuntu1.8
GET / HTTP/1.1
Host: mob-xxxx.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 05 Mar 2015 19:55:28 GMT
Server: nginx/1.2.1
Content-Type: text/html
Set-Cookie: s=1; path=/
X-Powered-By: PHP/5.4.6-1ubuntu1.8
Second query (visit from search engine):
GET / HTTP/1.1
Host: mob-xxxx.net
Referer: http://www.google.com/search?q=mob-xxxx.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mob-xxxx.net
Referer: http://www.google.com/search?q=mob-xxxx.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mob-xxxx.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://mob-xxxx.net/
Result: mob-xxxx.net is not infected or malware details are not published yet.
Result: mob-xxxx.net is not infected or malware details are not published yet.