Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://sergino.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: sergino.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Tue, 15 Jul 2014 18:35:11 GMT Location: http://alfsystem.com.my/includes/domit/1.php Server: nginx/1.4.4 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17-pl0-gentoo | malicious |
URL: http://alfsystem.com.my/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: alfsystem.com.my Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 15 Jul 2014 18:35:11 GMT Location: http://www.csra.de/includes/domit/1.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.23 | malicious |
URL: http://www.csra.de/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: www.csra.de Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 15 Jul 2014 18:35:11 GMT Location: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.30 | malicious |
URL: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php (imitation of visitor from search engine) GET /components/com_user/views/login/tmpl/1/all3.php HTTP/1.1 Host: jbtconsultinggroup.com Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 15 Jul 2014 18:35:12 GMT Location: http://google.ru Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | malicious |
Scanned pages/files
Request | Server response | Status |
http://sergino.ru/ | 200 OK Content-Length: 15260 Content-Type: text/html | clean |
http://sergino.ru/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://sergino.ru/modules/mod_ariyuimenu/mod_ariyuimenu/js/yui.combo.js | 200 OK Content-Length: 136091 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof YAHOO=="undefined"||!YAHOO){var YAHOO={};}YAHOO.namespace=function(){var A=arguments,E=null,C,B,D;for(C=0;C<A.length;C=C+1){D=(""+A[C]).split(".");E=YAHOO;for(B=(D[0]=="YAHOO")?1:0;B<D.length;B=B+1){E[D[B]]=E[D[B]]||{};E=E[D[B]];}}return E;};YAHOO.log=function(D,A,C){var B=YAHOO.widget.Logger;if(B&&B.log){return B.log(D,A,C);}else{return false;}};YAHOO.register=function(A,E,D){var I=YAHOO.env.modules,B,H,G,F,C;if(!I[A]){I[A]={versions:[],builds:[]};}B=I[A];H=D.version;G=D Antivirus reports:
| ||
http://sergino.ru/templates/a216/script.js | 200 OK Content-Length: 8647 Content-Type: application/x-javascript | clean |
http://sergino.ru/news | 200 OK Content-Length: 14634 Content-Type: text/html | clean |
http://sergino.ru/obyavleniya | 200 OK Content-Length: 13785 Content-Type: text/html | clean |
http://sergino.ru/municslugba/konkursydolgnosti | 200 OK Content-Length: 13656 Content-Type: text/html | clean |
http://sergino.ru/municslugba/vacancy | 200 OK Content-Length: 13646 Content-Type: text/html | clean |
http://sergino.ru/municzakaz | 200 OK Content-Length: 14691 Content-Type: text/html | clean |
http://sergino.ru/feedback | 200 OK Content-Length: 14698 Content-Type: text/html | clean |
http://sergino.ru/contacts | 200 OK Content-Length: 13653 Content-Type: text/html | clean |
http://sergino.ru/glava/iographiya | 200 OK Content-Length: 13566 Content-Type: text/html | clean |
http://sergino.ru/glava/polnomochglavy | 200 OK Content-Length: 13567 Content-Type: text/html | clean |
http://sergino.ru/glava/otchetorabote | 200 OK Content-Length: 13573 Content-Type: text/html | clean |
http://sergino.ru/administration/struktura | 200 OK Content-Length: 13627 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sergino.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sergino.ru/
Result: sergino.ru is not infected or malware details are not published yet.
Result: sergino.ru is not infected or malware details are not published yet.