Scanned pages/files
Request | Server response | Status |
http://ruxxx-mobi.net/ | 200 OK Content-Length: 2396 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.4.4.min.js | 200 OK Content-Length: 78601 Content-Type: application/x-javascript | clean |
http://ruxxx-mobi.net/themes/restore1/script/main.js | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://ruxxx-mobi.net/themes/restore1/script/main | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://ruxxx-mobi.net/terms | 200 OK Content-Length: 25293 Content-Type: text/html | clean |
http://ruxxx-mobi.net/test404page.js | 404 Not Found Content-Length: 2296 Content-Type: text/html | clean |
http://ruxxx-mobi.net/main | 200 OK Content-Length: 3762 Content-Type: text/html | clean |
http://ruxxx-mobi.net/subscribe | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 06 Mar 2015 01:46:31 GMT Location: http://ya.ru/ Server: nginx/1.2.1 Content-Type: text/html Set-Cookie: s=1; path=/ Set-Cookie: param_pagenewuser=http%3A%2F%2Fruxxx-mobi.net%2Freturn; path=/ X-Powered-By: PHP/5.4.6-1ubuntu1.8 | clean |
http://ya.ru/ | 200 Ok Content-Length: 11321 Content-Type: text/html | clean |
http://ya.ru//yastatic.net/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 79104 Content-Type: text/html | clean |
http://ya.ru//yastatic.net/www/2.261/v12/pages-desktop/error404/_error404.ru.js/ | 404 Not Found Content-Length: 79136 Content-Type: text/html | clean |
http://ya.ru//www.yandex.ru/ | 404 Not Found Content-Length: 79072 Content-Type: text/html | clean |
http://ya.ru//maps.yandex.ru/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 06 Mar 2015 01:49:14 GMT Location: http://maps.yandex.ru Server: nginx Content-Length: 154 Content-Type: text/html | clean |
http://maps.yandex.ru/ | 200 OK Content-Length: 51396 Content-Type: text/html | suspicious |
Suspicious code found <table class="b-head-userinfo b-head-userinfo_is-bem_yes i-bem i-bem" onclick="return {'b-head-userinfo':{name:'b-head-userinfo'}}"><tr><td class="b-head-userinfo__td"></td><td class="b-head-userinfo__entry"><a class="b-link b-link_pseudo_yes" href="https://passport.yandex.ru//passport?mode=auth&msg=maps&retpath=http%3A%2F%2Fmaps.yandex.ru%2F" onmousedown="Lego.ch('maps.login.enter',this)"><span class="b-link__inner">ÐойÑи</span></a><form class="b-domik b-domik_type_popup i-bem i-hidden" action="https://passport.yandex.ru//passport?mode=auth&from=maps&twoweeks=yes&retpath=http%3A%2F%2Fmaps.yandex.ru%2F" method="post" onclick="return {'b-domik':{name:'b-domik_type_popup',title:''}}"><input name="login"><input name="passwd" type="password"><input name="twoweeks" type="checkbox" value="no"></form></td></tr></table> | ||
http://maps.yandex.ru/print/ | 200 OK Content-Length: 6814 Content-Type: text/html | clean |
http://maps.yandex.ru//yandex.st/swf/swfobject/2.2-yandex1/_swfobject.js/ | 404 Not Found Content-Length: 79332 Content-Type: text/html | clean |
http://maps.yandex.ru//yastatic.net/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 79320 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ruxxx-mobi.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 06 Mar 2015 01:46:29 GMT
Server: nginx/1.2.1
Content-Type: text/html
Set-Cookie: s=1; path=/
X-Powered-By: PHP/5.4.6-1ubuntu1.8
GET / HTTP/1.1
Host: ruxxx-mobi.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 06 Mar 2015 01:46:29 GMT
Server: nginx/1.2.1
Content-Type: text/html
Set-Cookie: s=1; path=/
X-Powered-By: PHP/5.4.6-1ubuntu1.8
Second query (visit from search engine):
GET / HTTP/1.1
Host: ruxxx-mobi.net
Referer: http://www.google.com/search?q=ruxxx-mobi.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ruxxx-mobi.net
Referer: http://www.google.com/search?q=ruxxx-mobi.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ruxxx-mobi.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ruxxx-mobi.net/
Result: ruxxx-mobi.net is not infected or malware details are not published yet.
Result: ruxxx-mobi.net is not infected or malware details are not published yet.