Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=st.100klientov.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://st.100klientov.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://st.100klientov.ru/ | HTTP/1.1 302 Found Connection: close Date: Sun, 29 Jun 2014 10:12:07 GMT Location: http://help-cms.ru/domain_not_connected/ Server: nginx Content-Length: 224 Content-Type: text/html; charset=iso-8859-1 | clean |
http://help-cms.ru/domain_not_connected/ | 404 Not Found Content-Length: 16941 Content-Type: text/html | clean |
http://help-cms.ru/adminzone/js/lang.js | 200 OK Content-Length: 93623 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var umihost_lang = { data: {"az_scripts.contenttreeview.action_with_selected":"\u0414\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441 \u043e\u0442\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u043c\u0438","az_scripts.contenttreeview.delete":"\u0423\u0434\u0430\u043b\u0438\u0442\u044c","az_scripts.contenttreeview.show_in_menu":"\u041e\u0442\u043e\u0431\u0440\u0430\u0436\u0430\u0442\u044c \u0432 \u043c\u0435\u043d\u044e","az_scripts.contenttreeview.hide_from_menu":"\u041d\u0435 \u043e\u0442\u04 i18n: function(key, params) { if (typeof(this.data[ key ]) == 'undefined') { return ''; } var str = this.data[ key ]; for(var param in params) { str = str.replace(param, params[param]); } return str; } }; Antivirus reports:
| ||
http://st.100klientov.ru/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sun, 29 Jun 2014 10:12:09 GMT Location: http://help-cms.ru/domain_not_connected/ Server: nginx Content-Length: 224 Content-Type: text/html; charset=iso-8859-1 | clean |
http://help-cms.ru/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sun, 29 Jun 2014 10:12:09 GMT Location: http://help-cms.ru/domain_not_connected/ Server: nginx Content-Length: 224 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: st.100klientov.ru
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sun, 29 Jun 2014 10:12:07 GMT
Location: http://help-cms.ru/domain_not_connected/
Server: nginx
Content-Length: 224
Content-Type: text/html; charset=iso-8859-1
...224 bytes of data.
GET / HTTP/1.1
Host: st.100klientov.ru
Result:
HTTP/1.1 302 Found
Connection: close
Date: Sun, 29 Jun 2014 10:12:07 GMT
Location: http://help-cms.ru/domain_not_connected/
Server: nginx
Content-Length: 224
Content-Type: text/html; charset=iso-8859-1
...224 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: st.100klientov.ru
Referer: http://www.google.com/search?q=st.100klientov.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: st.100klientov.ru
Referer: http://www.google.com/search?q=st.100klientov.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.