Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=podrabotka-msk.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://podrabotka-msk.ru/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://podrabotka-msk.ru/ | 200 ok Content-Length: 67884 Content-Type: text/html | clean |
http://podrabotka-msk.ru/rdo100.js?PHPSESSID=706f647261626f7467386d7060727571 | 200 ok Content-Length: 532 Content-Type: text/plain | suspicious |
Page code contains blacklisted domain: yourmine.ru document.writeln('<scri'+'pt src="http://yourmine.ru/cgi-bin/mr.cgi"></scri'+'pt>');document.writeln('<scr'+'ipt type="text/javascript">var _paq = _paq || [];_paq.push(["trackPageView"]);_paq.push(["enableLinkTracking"]);(function() {var u="/piwik/";_paq.push(["setTrackerUrl", u+"piwik.php"]);_paq.push(["setSiteId", "?"]);var d=document, g=d.createElement("script"), s=d.getElementsByTagName("script")[0]; g.type="text/javascript";g.defer=true; g.async=true; g.src=u+"piwik.js"; s.parentNode.insertBefore(g,s);})();</sc'+'ript>'); | ||
http://podrabotka-msk.ru/test404page.js | 404 not found Content-Length: 196 Content-Type: text/html | clean |
http://podrabotka-msk.ru/odp100.js?PHPSESSID=706f647261626f7463366d7280727571 | 200 ok Content-Length: 293 Content-Type: text/plain | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21183 Content-Type: text/javascript | clean |
http://podrabotka-msk.ru/odp100.js?PHPSESSID=706f647261626f7467286d7015727571 | 200 ok Content-Length: 292 Content-Type: text/plain | clean |
http://podrabotka-msk.ru/files/tabber.js | 200 ok Content-Length: 15515 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: podrabotka-msk.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Fri, 22 Aug 2014 02:23:31 GMT
Server: nginx/1.2.0
Content-Length: 67884
Content-Type: text/html; charset=utf-8
Expires: Fri, 22 Aug 2014 02:23:31 GMT
...67884 bytes of data.
GET / HTTP/1.1
Host: podrabotka-msk.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Fri, 22 Aug 2014 02:23:31 GMT
Server: nginx/1.2.0
Content-Length: 67884
Content-Type: text/html; charset=utf-8
Expires: Fri, 22 Aug 2014 02:23:31 GMT
...67884 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: podrabotka-msk.ru
Referer: http://www.google.com/search?q=podrabotka-msk.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: podrabotka-msk.ru
Referer: http://www.google.com/search?q=podrabotka-msk.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.