Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sanscrit.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 15 Aug 2014 16:05:32 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=windows-1251
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Fri, 15 Aug 2014 16:05:32 GMT
Set-Cookie: 7f9c38cc58d156e651c10553a0e0f1e8=-; path=/
Set-Cookie: mosvisitor=1
GET / HTTP/1.1
Host: sanscrit.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 15 Aug 2014 16:05:32 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=windows-1251
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Fri, 15 Aug 2014 16:05:32 GMT
Set-Cookie: 7f9c38cc58d156e651c10553a0e0f1e8=-; path=/
Set-Cookie: mosvisitor=1
Second query (visit from search engine):
GET / HTTP/1.1
Host: sanscrit.ru
Referer: http://www.google.com/search?q=sanscrit.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sanscrit.ru
Referer: http://www.google.com/search?q=sanscrit.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://sanscrit.ru/ | 200 OK Content-Length: 34295 Content-Type: text/html | clean |
http://sanscrit.ru/modules/ja_transmenu/transmenu.js | 200 OK Content-Length: 34097 Content-Type: application/javascript | clean |
http://sanscrit.ru/component/option,com_frontpage/Itemid,1/ | 200 OK Content-Length: 34338 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/15/32/ | 200 OK Content-Length: 26320 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/16/35/ | 200 OK Content-Length: 20533 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/17/36/ | 200 OK Content-Length: 39282 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/29/48/ | 200 OK Content-Length: 22091 Content-Type: text/html | clean |
http://sanscrit.ru/content/section/9/78/ | 200 OK Content-Length: 12639 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/31/50/ | 200 OK Content-Length: 24037 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/56/76/ | 200 OK Content-Length: 35240 Content-Type: text/html | clean |
http://sanscrit.ru/component/option,com_weblinks/Itemid,22/ | 200 OK Content-Length: 12189 Content-Type: text/html | clean |
http://sanscrit.ru/component/option,com_contact/Itemid,3/ | 200 OK Content-Length: 19012 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/49/83/ | 200 OK Content-Length: 38081 Content-Type: text/html | clean |
http://sanscrit.ru/content/category/4/13/26/ | 200 OK Content-Length: 15639 Content-Type: text/html | clean |
http://sanscrit.ru/content/view/20/88/ | 200 OK Content-Length: 37286 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sanscrit.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sanscrit.ru/
Result: sanscrit.ru is not infected or malware details are not published yet.
Result: sanscrit.ru is not infected or malware details are not published yet.