Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pokerwww.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: pokerwww.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Jul 2014 20:48:20 GMT
Server: nginx/1.4.3
Content-Type: text/html; charset=UTF-8
X-Pingback: http://pokerwww.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: pokerwww.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 26 Jul 2014 20:48:20 GMT
Server: nginx/1.4.3
Content-Type: text/html; charset=UTF-8
X-Pingback: http://pokerwww.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: pokerwww.ru
Referer: http://www.google.com/search?q=pokerwww.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: pokerwww.ru
Referer: http://www.google.com/search?q=pokerwww.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://pokerwww.ru/ | 200 OK Content-Length: 22994 Content-Type: text/html | clean |
http://pokerwww.ru/wp-content/themes/WPG138/js/jquery-1.3.2.min.js | 200 OK Content-Length: 57272 Content-Type: application/x-javascript | clean |
http://pokerwww.ru/wp-content/themes/WPG138/js/superfish.js | 200 OK Content-Length: 3827 Content-Type: application/x-javascript | clean |
http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a65e1d93cd75e94 | 200 OK Content-Length: 6853 Content-Type: text/javascript | clean |
http://pokerwww.ru/feed/ | 200 OK Content-Length: 14423 Content-Type: text/xml | clean |
http://pokerwww.ru/test404page.js | 404 Not Found Content-Length: 14006 Content-Type: text/html | clean |
http://pokerwww.ru/go/pokersavvy | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Jul 2014 20:48:23 GMT Location: http://www.pokersavvy.com/ru/play-poker-get-cash-ps#20662 Server: nginx/1.4.3 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.pokersavvy.com/ru/play-poker-get-cash-ps | 200 OK Content-Length: 37027 Content-Type: text/html | clean |
http://www.pokersavvy.com/themes/pokersavvy/script/pokersavvy.js | 200 OK Content-Length: 17704 Content-Type: application/x-javascript | clean |
http://pokerwww.ru/_js/cookie_tools.js | 404 Not Found Content-Length: 14011 Content-Type: text/html | clean |
http://pokerwww.ru/go/titanpoker | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Jul 2014 20:48:28 GMT Location: http://online.titanpoker.com/promoRedirect?key=ej0xNDI5OTcwMyZsPTE0Mjk5NjcwJnA9NDY5NDc5 Server: nginx/1.4.3 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://online.titanpoker.com/promoredirect?key=ej0xndi5otcwmyzspte0mjk5njcwjna9ndy5ndc5 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Jul 2014 20:44:05 GMT Location: http://titanpoker.com Content-Type: text/html; charset=iso-8859-1 | clean |
http://titanpoker.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=1209600 Connection: close Date: Sat, 26 Jul 2014 20:48:28 GMT Location: http://www.titanpoker.com/ Server: Apache Vary: Accept-Encoding Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 09 Aug 2014 20:48:28 GMT | clean |
http://www.titanpoker.com/ | 200 OK Content-Length: 37622 Content-Type: text/html | clean |
http://cachewww.titanpoker.com/js/js_47845d16aa1d1f0964b466aeb3c283c3d4d6246c.js | 200 OK Content-Length: 300756 Content-Type: application/javascript | clean |
http://pokerwww.ru//service.maxymiser.net/cdn/titanpoker/js/mmcore.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 26 Jul 2014 20:48:31 GMT Pragma: no-cache Location: http://pokerwww.ru/service.maxymiser.net/cdn/titanpoker/js/mmcore.js/ Server: nginx/1.4.3 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://pokerwww.ru/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://pokerwww.ru/service.maxymiser.net/cdn/titanpoker/js/mmcore.js/ | 404 Not Found Content-Length: 14041 Content-Type: text/html | clean |
http://pokerwww.ru/go/rivapoker | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 26 Jul 2014 20:48:32 GMT Location: http://banner.rivapoker.com/cgi-bin/redir.cgi?id=N&member=mara79&profile=free20 Server: nginx/1.4.3 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://banner.rivapoker.com/cgi-bin/redir.cgi?id=n&member=mara79&profile=free20 | HTTP/1.1 302 Found Location: http://www.rivapoker.com/ Content-Length: 209 Content-Type: text/html; charset=iso-8859-1 P3P: CP="NON DEVa TAIa OUR BUS" Set-Cookie: banner_click=mara79,,free20,*,*; expires=Tue, 29-Jul-2014 20:48:33 GMT; domain=.rivapoker.com; path=/ Set-Cookie: banner_exiturl=*; expires=Tue, 29-Jul-2014 20:48:33 GMT; domain=.rivapoker.com; path=/ Set-Cookie: banner_domainclick=mara79,,free20,*,*; expires=Tue, 29-Jul-2014 20:48:33 GMT; domain=.rivapoker.com; path=/ X-Cnection: close | clean |
http://www.rivapoker.com/ | 200 OK Content-Length: 25773 Content-Type: text/html | clean |
http://www.rivapoker.com/themes/rivapokerv2/jscripts/js.js | 200 OK Content-Length: 2643 Content-Type: application/javascript | clean |
http://www.rivapoker.com/themes/rivapokerv2/jscripts/jquery-1.4.1.min.js | 200 OK Content-Length: 70843 Content-Type: application/javascript | clean |