Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: rwings.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 01 Feb 2015 21:30:40 GMT
Pragma: no-cache
Server: nginx/1.7.4
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 01 Feb 2015 21:30:40 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 012cbafc1e934296b1a38b9a61c5f119=fehcm7vtnfukup9r4a89t56jm6; path=/
Set-Cookie: ja_purity_tpl=ja_purity; expires=Fri, 22-Jan-2016 21:30:40 GMT; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
GET / HTTP/1.1
Host: rwings.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 01 Feb 2015 21:30:40 GMT
Pragma: no-cache
Server: nginx/1.7.4
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 01 Feb 2015 21:30:40 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 012cbafc1e934296b1a38b9a61c5f119=fehcm7vtnfukup9r4a89t56jm6; path=/
Set-Cookie: ja_purity_tpl=ja_purity; expires=Fri, 22-Jan-2016 21:30:40 GMT; path=/
X-Powered-By: PHP/5.2.17-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: rwings.ru
Referer: http://www.google.com/search?q=rwings.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: rwings.ru
Referer: http://www.google.com/search?q=rwings.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://rwings.ru/ | 200 OK Content-Length: 20987 Content-Type: text/html | clean |
http://rwings.ru/media/system/js/caption.js | 200 OK Content-Length: 1721 Content-Type: application/x-javascript | clean |
http://rwings.ru/plugins/content/highslide/highslide-full.packed.js | 200 OK Content-Length: 47973 Content-Type: application/x-javascript | clean |
http://rwings.ru/plugins/content/highslide/easing_equations.js | 200 OK Content-Length: 9387 Content-Type: application/x-javascript | clean |
http://rwings.ru/plugins/content/highslide/swfobject.js | 200 OK Content-Length: 9759 Content-Type: application/x-javascript | clean |
http://rwings.ru/plugins/content/highslide/config/js/highslide-sitesettings.js | 200 OK Content-Length: 8439 Content-Type: application/x-javascript | clean |
http://rwings.ru/components/com_jcomments/js/jcomments-v2.0.js | 200 OK Content-Length: 26433 Content-Type: application/x-javascript | clean |
http://rwings.ru/components/com_jcomments/libraries/joomlatune/ajax.js | 200 OK Content-Length: 3978 Content-Type: application/x-javascript | clean |
http://rwings.ru/templates/ja_purity/js/ja.script.js | 200 OK Content-Length: 3207 Content-Type: application/x-javascript | clean |
http://rwings.ru/templates/ja_purity/js/ja.rightcol.js | 200 OK Content-Length: 1695 Content-Type: application/x-javascript | clean |
http://rwings.ru/rwings.doc | 200 OK Content-Length: 46080 Content-Type: application/msword | clean |
http://rwings.ru/test404page.js | 404 Not Found Content-Length: 1103 Content-Type: text/html | clean |
http://rwings.ru/component/content/article/124-ny-2015.html | 200 OK Content-Length: 13377 Content-Type: text/html | clean |
http://rwings.ru/component/content/article/ | 404 Not Found Content-Length: 1852 Content-Type: text/html | clean |
http://rwings.ru/index.php | 200 OK Content-Length: 20996 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=rwings.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://rwings.ru/
Result: rwings.ru is not infected or malware details are not published yet.
Result: rwings.ru is not infected or malware details are not published yet.