Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: pokerclock.ru
Result:
GET / HTTP/1.1
Host: pokerclock.ru
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: pokerclock.ru
Referer: http://www.google.com/search?q=pokerclock.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: pokerclock.ru
Referer: http://www.google.com/search?q=pokerclock.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.pokerclock.ru/ | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.pokerclock.ru/test404page.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 14 Jan 2015 19:35:33 GMT Location: http://restoran-bambuk.ru/404?keyword=test404page.rar Server: nginx/1.4.3 Content-Type: text/html X-Powered-By: PHP/5.4.21-1~dotdeb.1 | clean |
http://restoran-bambuk.ru/404?keyword=test404page.rar | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Wed, 14 Jan 2015 19:35:33 GMT Pragma: no-cache Location: http://fast-rutracker.in/redirect/redirect.php?site=11&sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Wed, 14 Jan 2015 19:35:33 GMT X-Powered-By: PHP/5.4.34 | clean |
http://fast-rutracker.in/redirect/redirect.php?site=11&sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 14 Jan 2015 19:49:52 GMT Location: http://dl32.softportalbcc.name?sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip Server: nginx Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.27 | clean |
http://dl32.softportalbcc.name?sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip/ | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Wed, 14 Jan 2015 19:35:33 GMT Pragma: no-cache Location: /?page=lending&key=archive755217.zip%2F Server: nginx/1.0.14 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sat, 17 Jan 2015 19:35:33 GMT Set-Cookie: PHPSESSID=e9jpv3e5broq9nuibjhm2qlkr7; path=/ X-Powered-By: PHP/5.3.10 | clean |
http://dl32.softportalbcc.name?sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip/?page=lending&key=archive755217.zip%2f | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Wed, 14 Jan 2015 19:35:34 GMT Pragma: no-cache Location: /?page=lending&key=archive755217.zip%2F Server: nginx/1.0.14 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sat, 17 Jan 2015 19:35:34 GMT Set-Cookie: PHPSESSID=7pi592gbac1kl1pj0hjn979923; path=/ X-Powered-By: PHP/5.3.10 | clean |
http://dl32.softportalbcc.name?sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip/test404page.js | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Wed, 14 Jan 2015 19:35:34 GMT Pragma: no-cache Location: /?page=lending&key=archive755217.zip%2Ftest404page.js Server: nginx/1.0.14 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sat, 17 Jan 2015 19:35:34 GMT Set-Cookie: PHPSESSID=jcf2nk7uoei0tmj2pc171kvoj0; path=/ X-Powered-By: PHP/5.3.10 | clean |
http://dl32.softportalbcc.name?sid=491349525&buyer_sid=911441499&page=lending&key=archive755217.zip/?page=lending&key=archive755217.zip%2ftest404page.js | HTTP/1.1 302 Found Cache-Control: max-age=259200 Connection: close Date: Wed, 14 Jan 2015 19:35:34 GMT Pragma: no-cache Location: /?page=lending&key=archive755217.zip%2Ftest404page.js Server: nginx/1.0.14 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sat, 17 Jan 2015 19:35:34 GMT Set-Cookie: PHPSESSID=2jnqj5mq630jsns06roeehaes5; path=/ X-Powered-By: PHP/5.3.10 | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pokerclock.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://pokerclock.ru/
Result: pokerclock.ru is not infected or malware details are not published yet.
Result: pokerclock.ru is not infected or malware details are not published yet.