Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.stroyteching.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.stroyteching.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Cache-Control: post-check=0, pre-check=0 Connection: close Date: Tue, 16 Sep 2014 02:36:39 GMT Pragma: no-cache ETag: 6666cd76f96956469e7be39d750cc7d9 Location: http://web-redirect.ru/?web Server: nginx/1.4.4 Content-Type: text/html Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Tue, 16 Sep 2014 02:36:39 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: _cutt_caches_images=1410834999; expires=Wed, 17-Sep-2014 02:36:39 GMT; path=/ Set-Cookie: 278df1179fb65b6f9b67a87b08adaa16=1epvf4skain7m63va9nl2p8as5; path=/ X-Powered-By: PHP/5.2.17-pl0-gentoo | malicious |
URL: http://web-redirect.ru/?web (imitation of visitor from search engine) GET /?web HTTP/1.1 Host: web-redirect.ru Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Tue, 16 Sep 2014 02:36:39 GMT Pragma: no-cache Location: http://honeycake.com.ua/components/com_weblinks/2/separator.php Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Tue, 16 Sep 2014 02:36:39 GMT X-Powered-By: PHP/5.3.3 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://www.stroyteching.ru/ | 200 OK Content-Length: 14753 Content-Type: text/html | clean |
http://www.stroyteching.ru/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/plugins/content/highslide/highslide-with-html.js | 200 OK Content-Length: 60863 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var hs = { graphicsDir : 'plugins/content/highslide/graphics/', restoreCursor : 'zoomout.cur', expandSteps : 10, expandDuration : 250, restoreSteps : 10, restoreDuration : 250, marginLeft : 15, marginRight : 15, marginTop : 15, marginBottom : 15, zIndexCounter : 1001, restoreTitle : '', loadingText : 'ÐагÑÑзка...', loadingTitle : 'ÐажмиÑе Ð´Ð»Ñ Ð¾ÑменÑ', loadingOpacity : 0.75, focusTitle : 'ÐажмиÑе } } hs.getElementByClass(this.content, 'DIV', 'highslide-body').innerHTML = s; this.onLoad(); for (var x in this) this[x] = null; } }; var HsExpander = hs.Expander; hs.addEventListener(document, 'mousedown', hs.mouseClickHandler); hs.addEventListener(document, 'mouseup', hs.mouseClickHandler); hs.addEventListener(window, 'load', hs.preloadImages); hs.addEventListener(window, 'load', hs.preloadAjax); Antivirus reports:
| ||
http://www.stroyteching.ru/plugins/content/highslide/swfobject.js | 200 OK Content-Length: 6889 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/plugins/content/highslide/do_cookie.js | 200 OK Content-Length: 2457 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/templates/stroyteching/ja_menus/ja_cssmenu/mootools.v1.1.js | 200 OK Content-Length: 180531 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/templates/stroyteching/ja_menus/ja_cssmenu/ja.cssmenu.js | 200 OK Content-Length: 4662 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/templates/stroyteching/scripts/ja.script.js | 200 OK Content-Length: 4308 Content-Type: application/x-javascript | clean |
http://www.stroyteching.ru/index.php | 200 OK Content-Length: 17611 Content-Type: text/html | clean |
http://www.stroyteching.ru/home.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:42 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://medicgbud.ru/ | 500 Server closed connection without sending any data back Content-Length: 105 Content-Type: text/plain | clean |
http://medicgbud.ru/test404page.js | 500 Server closed connection without sending any data back Content-Length: 105 Content-Type: text/plain | clean |
http://www.stroyteching.ru/licenzii.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:43 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/obekt.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:43 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/partner.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:43 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/contacts.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:43 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/index.php?view=article&id=45:2008-03-17-16-56-59&tmpl=component&print=1&layout=default&page= | 200 OK Content-Length: 9179 Content-Type: text/html | clean |
http://www.stroyteching.ru/naprav.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:44 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/ingsys.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:44 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/obor.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:44 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/service.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:44 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/obuch.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:45 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/vakans.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:45 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/intrest-.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:45 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/plitkaikamen.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:45 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/vibropress.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:45 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.stroyteching.ru/saddorplitka.html | HTTP/1.1 302 Found Connection: close Date: Tue, 16 Sep 2014 02:36:46 GMT Location: http://medicgbud.ru/ Server: nginx/1.4.4 Content-Length: 376 Content-Type: text/html; charset=iso-8859-1 | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=stroyteching.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://stroyteching.ru/
Result: stroyteching.ru is not infected or malware details are not published yet.
Result: stroyteching.ru is not infected or malware details are not published yet.