Scanned pages/files
Request | Server response | Status |
http://smartwatch-2.ru/ | 200 OK Content-Length: 26570 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (document.getElementById("form_plugins_url")) { var plugin_url = document.getElementById("form_plugins_url").value; } else { var plugin_url = ""; } Antivirus reports:
| ||
http://smartwatch-2.ru/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ajax.js?ver=3.8.4 | 200 OK Content-Length: 33 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/vkontakte-api/js/callback.js?ver=3.8.4 | 200 OK Content-Length: 4977 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/main_front_end.js?ver=3.8.4 | 200 OK Content-Length: 56098 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/calendar.js?ver=3.8.4 | 200 OK Content-Length: 36556 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/calendar-setup.js?ver=3.8.4 | 200 OK Content-Length: 4919 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/calendar_function.js?ver=3.8.4 | 200 OK Content-Length: 15039 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/jquery-ui.js?ver=3.8.4 | 200 OK Content-Length: 300956 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/plugins/form-maker/js/jquery.ui.slider.js?ver=3.8.4 | 200 OK Content-Length: 17595 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/themes/business-lite.3.1.59/core/library/js/foundation/jquery.orbit.js?ver=3.8.4 | 200 OK Content-Length: 19374 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/themes/business-lite.3.1.59/core/library/js/foundation/app.js?ver=3.8.4 | 200 OK Content-Length: 2465 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/themes/business-lite.3.1.59/core/library/js/foundation/jquery.placeholder.min.js?ver=3.8.4 | 200 OK Content-Length: 1637 Content-Type: application/x-javascript | clean |
http://smartwatch-2.ru/wp-content/themes/business-lite.3.1.59/core/library/js/foundation/jquery.reveal.js?ver=3.8.4 | 200 OK Content-Length: 5282 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: smartwatch-2.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 09 Aug 2014 04:56:25 GMT
Pragma: no-cache
Server: nginx/1.4.5
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://smartwatch-2.ru/?p=6>; rel=shortlink
Set-Cookie: PHPSESSID=9d778716597a4b5ec3f0d73fcc2c0ec0; path=/
X-Pingback: http://smartwatch-2.ru/xmlrpc.php
X-Powered-By: PHP/5.3.13
GET / HTTP/1.1
Host: smartwatch-2.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 09 Aug 2014 04:56:25 GMT
Pragma: no-cache
Server: nginx/1.4.5
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://smartwatch-2.ru/?p=6>; rel=shortlink
Set-Cookie: PHPSESSID=9d778716597a4b5ec3f0d73fcc2c0ec0; path=/
X-Pingback: http://smartwatch-2.ru/xmlrpc.php
X-Powered-By: PHP/5.3.13
Second query (visit from search engine):
GET / HTTP/1.1
Host: smartwatch-2.ru
Referer: http://www.google.com/search?q=smartwatch-2.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: smartwatch-2.ru
Referer: http://www.google.com/search?q=smartwatch-2.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=smartwatch-2.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://smartwatch-2.ru/
Result: smartwatch-2.ru is not infected or malware details are not published yet.
Result: smartwatch-2.ru is not infected or malware details are not published yet.