Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: otstrel.ru
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sun, 08 Mar 2015 12:05:54 GMT
Pragma: private
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html; charset=utf-8
Set-Cookie: bbsessionhash=c43b56746ca1e18a08c7f122b3757abf; path=/; domain=.otstrel.ru; HttpOnly
Set-Cookie: bblastvisit=1425816354; expires=Mon, 07-Mar-2016 12:05:54 GMT; path=/; domain=.otstrel.ru
Set-Cookie: bblastactivity=0; expires=Mon, 07-Mar-2016 12:05:54 GMT; path=/; domain=.otstrel.ru
X-Powered-By: PHP/5.2.17
X-UA-Compatible: IE=7
GET / HTTP/1.1
Host: otstrel.ru
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sun, 08 Mar 2015 12:05:54 GMT
Pragma: private
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html; charset=utf-8
Set-Cookie: bbsessionhash=c43b56746ca1e18a08c7f122b3757abf; path=/; domain=.otstrel.ru; HttpOnly
Set-Cookie: bblastvisit=1425816354; expires=Mon, 07-Mar-2016 12:05:54 GMT; path=/; domain=.otstrel.ru
Set-Cookie: bblastactivity=0; expires=Mon, 07-Mar-2016 12:05:54 GMT; path=/; domain=.otstrel.ru
X-Powered-By: PHP/5.2.17
X-UA-Compatible: IE=7
Second query (visit from search engine):
GET / HTTP/1.1
Host: otstrel.ru
Referer: http://www.google.com/search?q=otstrel.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: otstrel.ru
Referer: http://www.google.com/search?q=otstrel.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://otstrel.ru/ | 200 OK Content-Length: 58630 Content-Type: text/html | clean |
http://otstrel.ru/forum/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=387 | 200 OK Content-Length: 36628 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/clientscript/yui/connection/connection-min.js?v=387 | 200 OK Content-Length: 11604 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/clientscript/vbulletin_global.js?v=387 | 200 OK Content-Length: 26028 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/clientscript/vbulletin_menu.js?v=387 | 200 OK Content-Length: 9441 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/clientscript/vbulletin_lightbox.js?v=387 | 200 OK Content-Length: 13003 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/clientscript/vbulletin_md5.js?v=387 | 200 OK Content-Length: 5464 Content-Type: application/x-javascript | clean |
http://otstrel.ru//mc.yandex.ru/metrika/watch.js/ | 200 OK Content-Length: 58690 Content-Type: text/html | clean |
http://otstrel.ru/forum/ | 200 OK Content-Length: 128349 Content-Type: text/html | clean |
http://otstrel.ru/forum/clientscript/vbulletin_read_marker.js?v=387 | 200 OK Content-Length: 3440 Content-Type: application/x-javascript | clean |
http://otstrel.ru/forum/register.php | 200 OK Content-Length: 17800 Content-Type: text/html | clean |
http://otstrel.ru/forum/index.php | 200 OK Content-Length: 128358 Content-Type: text/html | clean |
http://otstrel.ru/forum/faq.php | 200 OK Content-Length: 35731 Content-Type: text/html | clean |
http://otstrel.ru/forum/faq.php?nojs=1 | 200 OK Content-Length: 30959 Content-Type: text/html | clean |
http://otstrel.ru/forum/members/list/ | 200 OK Content-Length: 130823 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=otstrel.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://otstrel.ru/
Result: otstrel.ru is not infected or malware details are not published yet.
Result: otstrel.ru is not infected or malware details are not published yet.