Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://ruh-center.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: ruh-center.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Cache-Control: max-age=1 Connection: close Date: Mon, 01 Sep 2014 12:54:26 GMT Location: http://breakingbad.osa.pl/ Server: Apache/2.2.17 (Unix) PHP/5.2.17 Content-Length: 0 Content-Type: text/html Expires: Mon, 01 Sep 2014 12:54:27 GMT X-Powered-By: PHP/5.2.17 | malicious |
Scanned pages/files
Request | Server response | Status |
http://ruh-center.ru/ | 200 OK Content-Length: 13483 Content-Type: text/html | clean |
http://ruh-center.ru/misc/jquery.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/misc/drupal.js | 200 OK Content-Length: 24057 Content-Type: application/javascript | suspicious |
Suspicious code found | ||
http://ruh-center.ru/modules/jquery_update/compat-1.0.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/modules/lightbox2/js/auto_image_handling.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/modules/lightbox2/js/lightbox_video.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/modules/lightbox2/js/lightbox.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/modules/jquery_update/collapse-fix.js | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://ruh-center.ru/zayavka | 200 OK Content-Length: 53847 Content-Type: text/html | clean |
http://ruh-center.ru/offers | 200 OK Content-Length: 11808 Content-Type: text/html | clean |
http://www.101.ru/?an=infoplayw1&channel=124 | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, must-revalidate, no-cache, max-age=0, post-check=0, pre-check=0 Connection: close Date: Mon, 01 Sep 2014 12:54:29 GMT Pragma: no-cache Location: http://101.ru/?an=infoplayw1&channel=124 Server: nginx Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Mon, 01 Sep 2014 11:54:29 GMT Last-Modified: Mon, 01 Sep 2014 12:54:29 GMT Set-Cookie: setst=-1; expires=Mon, 01-Sep-2014 13:54:29 GMT; path=/ Set-Cookie: updTime=1409576069; expires=Tue, 01-Sep-2015 12:54:29 GMT; path=/ Set-Cookie: con=1409576069; expires=Tue, 01-Sep-2015 12:54:29 GMT; path=/ Set-Cookie: sid_101_ru=i5l69i242pjhco2ua61u03i582; path=/ Status: 404 Not Found X-Powered-By: PHP/5.3.10-1ubuntu3.11 | clean |
http://101.ru/?an=infoplayw1&channel=124 | 404 Not Found Content-Length: 25877 Content-Type: text/html | suspicious |
Suspicious code found <!--Rating@Mail.ru COUNTER--> <script language="JavaScript" type="text/javascript"><!-- d=document;var a='';a+=';r='+escape(d.referrer) js=10//--></script><script language="JavaScript1.1" type="text/javascript"><!-- a+=';j='+navigator.javaEnabled() js=11//--></script><script language="JavaScript1.2" type="text/javascript"><!-- s=screen;a+=';s='+s.width+'*'+s.height a+=';d='+(s.colorDepth?s.colorDepth:s.pixelDepth) target="_blank"><img src="http://counter.yadro.ru/logo?13.5" title="LiveInternet: показано ÑиÑло пÑоÑмоÑÑов за 24 ÑаÑа, поÑеÑиÑелей за 24 ÑаÑа и за ÑегоднÑ" alt="" border="0" width="88" height="31"></a><!--/LiveInternet--> <a href="http://top100.rambler.ru/top100/"><img src="http://top100-images.rambler.ru/top100/w1.gif" alt="Rambler's Top100" width="88" height="31" border="0"></a> Hidden iFrame found. size: 1x1 src: http://awaps.yandex.ru/0/9947/001001.htm <iframe src="http://awaps.yandex.ru/0/9947/001001.htm" width="1" height="1"
marginwidth="0" marginheight="0" hspace="0" vspace="0" frameborder="0"
scrolling="no" bordercolor="#000000"
style="left: -9999px; position: absolute;"> | ||
https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js | 200 OK Content-Length: 94840 Content-Type: text/javascript | clean |
http://www.101.ru/static/js/jquery/jquery-ui.custom.min.js?03 | 200 OK Content-Length: 208528 Content-Type: application/x-javascript | clean |
http://www.101.ru/static/js/mp.library.js?10 | 200 OK Content-Length: 18852 Content-Type: application/x-javascript | clean |
http://www.101.ru/design/include/101.common.js?017 | 200 OK Content-Length: 18294 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ruh-center.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ruh-center.ru/
Result: ruh-center.ru is not infected or malware details are not published yet.
Result: ruh-center.ru is not infected or malware details are not published yet.