Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://shar78.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: shar78.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 11 May 2014 21:25:53 GMT Location: http://mywifeishappy.com/ Server: nginx Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 | malicious |
URL: http://mywifeishappy.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: mywifeishappy.com Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Connection: close Date: Sun, 11 May 2014 21:24:06 GMT Location: http://slgsazuz.com Server: nginx Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.28 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://shar78.ru/ | 200 OK Content-Length: 25936 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.js | 200 OK Content-Length: 93435 Content-Type: text/javascript | clean |
http://shar78.ru/wp-content/themes/buisnezz/scripts/jquery.js | 200 OK Content-Length: 156836 Content-Type: application/javascript | clean |
http://shar78.ru/wp-content/themes/buisnezz/scripts/show.js | 200 OK Content-Length: 2916 Content-Type: application/javascript | clean |
http://stummann.net/steffen/google-analytics/jquery-1.6.5.min.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
http://stummann.net/test404page.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
http://userapi.com/js/api/openapi.js?47 | 200 OK Content-Length: 63942 Content-Type: application/x-javascript | clean |
http://odnaknopka.ru/ok1.js | 200 OK Content-Length: 761 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function NewOdnaknopka1() { this.init=function() { document.write('<a href="http://odnaknopka.ru/add/" onclick="window.open(\'http://odnaknopka.ru/add/?url=\'+encodeURIComponent(location.href)+\'&title=\'+encodeURIComponent(document.title),\'odnaknopka\',\'scrollbars=yes,menubar=no,width=600,height=500,left='+(document.body.clientWidth/2-300)+',top='+(document.body.clientHeight/2-250)+',resizable=yes,toolbar=no,location=no,status=no\');return false;"><img src="http://odnaknopka.ru/images/button.gif" width="136" height="16" alt="ОднаКнопка" title="ОднаКнопка" border="0"></a>'); } } odnaknopka1=new NewOdnaknopka1(); odnaknopka1.init(); Antivirus reports:
| ||
http://medicswap.com/js/widget.js | 500 Server closed connection without sending any data back Content-Length: 105 Content-Type: text/plain | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=shar78.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://shar78.ru/
Result: shar78.ru is not infected or malware details are not published yet.
Result: shar78.ru is not infected or malware details are not published yet.