Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=savo.eu
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://savo.eu/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: savo.eu
Result:
HTTP/1.1 404 Not Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 13 Jan 2015 17:37:55 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=3631656d5f3eb29e082cb4984da79bd7; path=/; domain=savo.eu
Set-Cookie: PHPSESSID=3631656d5f3eb29e082cb4984da79bd7; path=/; domain=savo.eu
Set-Cookie: temp_cookie=545392; expires=Fri, 08 Jan 2016 17:37:55 GMT; path=/; domain=savo.eu
GET / HTTP/1.1
Host: savo.eu
Result:
HTTP/1.1 404 Not Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 13 Jan 2015 17:37:55 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Vary: Accept-Encoding
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=3631656d5f3eb29e082cb4984da79bd7; path=/; domain=savo.eu
Set-Cookie: PHPSESSID=3631656d5f3eb29e082cb4984da79bd7; path=/; domain=savo.eu
Set-Cookie: temp_cookie=545392; expires=Fri, 08 Jan 2016 17:37:55 GMT; path=/; domain=savo.eu
Second query (visit from search engine):
GET / HTTP/1.1
Host: savo.eu
Referer: http://www.google.com/search?q=savo.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: savo.eu
Referer: http://www.google.com/search?q=savo.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://savo.eu/ | 404 Not Found Content-Length: 12467 Content-Type: text/html | clean |
http://savo.eu/js/hover.js | 200 OK Content-Length: 1451 Content-Type: text/javascript | clean |
http://savo.eu/js/header.js | 200 OK Content-Length: 3183 Content-Type: text/javascript | clean |
http://savo.eu/js/swfobject.js | 200 OK Content-Length: 10220 Content-Type: text/javascript | clean |
http://www.google-analytics.com/ga.js | 200 OK Content-Length: 40937 Content-Type: text/javascript | clean |
http://savo.eu/lib/im/ga-set.js | 200 OK Content-Length: 2842 Content-Type: text/javascript | clean |
http://savo.eu/js/globals.js.php | 200 OK Content-Length: 2518 Content-Type: text/html | clean |
http://savo.eu/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://savo.eu/js_custom/custom.globals.js.php | 200 OK Content-Length: 117 Content-Type: text/html | clean |
http://savo.eu/js/main.js | 200 OK Content-Length: 7490 Content-Type: text/javascript | clean |
http://savo.eu/js/elements.js | 200 OK Content-Length: 10719 Content-Type: text/javascript | clean |
http://savo.eu/js/ajax.js | 200 OK Content-Length: 4718 Content-Type: text/javascript | clean |
http://savo.eu/js/ajax_app.js | 200 OK Content-Length: 10116 Content-Type: text/javascript | clean |
http://savo.eu/js/jquery-1.3.2.min.js | 200 OK Content-Length: 57254 Content-Type: text/javascript | clean |
http://savo.eu/js/ui.datepicker.unpack.js | 200 OK Content-Length: 60784 Content-Type: text/javascript | clean |