Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://study-tour.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: study-tour.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Tue, 12 May 2015 16:19:11 GMT Location: http://web-redirect.ru/?web Server: Apache Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Tue, 12 May 2015 16:19:11 GMT Set-Cookie: _cutt_caches_images=1431447551; expires=Wed, 13-May-2015 16:19:11 GMT; path=/ | malicious |
URL: http://web-redirect.ru/?web (imitation of visitor from search engine) GET /?web HTTP/1.1 Host: web-redirect.ru Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Found Cache-Control: max-age=0 Connection: close Date: Tue, 12 May 2015 16:19:11 GMT Pragma: no-cache Location: http://cmsjoom.ru/components/com_weblinks/2/separator.php Server: nginx/1.0.15 Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Thu, 21 Jul 1977 07:30:00 GMT Last-Modified: Tue, 12 May 2015 16:19:11 GMT X-Powered-By: PHP/5.3.3 | suspicious |
Scanned pages/files
Request | Server response | Status |
http://study-tour.ru/ | 200 OK Content-Length: 8073 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.studycamp.ru ...[3008 bytes skipped]... gt; <div class="art-post-body"> <div class="art-post-inner"> <div class="art-postcontent"> 1<div class="art-article"><p>ÐÑ Ð½Ð°Ñ Ð¾Ð´Ð¸ÑеÑÑ <nobr>на ÑÐµÑ Ð½Ð¾Ð»Ð¾Ð³Ð¸ÑеÑком</nobr> ÑайÑе, <nobr>а длÑ</nobr> полноÑенной ÑабоÑÑ Ð¿ÐµÑейдиÑе пожалÑйÑÑа <nobr>на ÑайÑ</nobr> <a href="http://www.studycamp.ru"><span style="font-size: 12pt;">www.studycamp.ru</span></a> (лагеÑÑ) или <a href="http://www.study-centre.ru"><span style="font-size: 12pt;"><nobr>www.study-centre.ru</nobr></span></a> (обÑÑение <nobr>за ÑÑбежом)</nobr></p></div> </div> <div class="cleared"></div> </div> <div class="cleared"></div> </ ...[1212 bytes skipped]... | ||
http://study-tour.ru/media/system/js/mootools-core.js | 200 OK Content-Length: 96362 Content-Type: application/javascript | clean |
http://study-tour.ru/media/system/js/core.js | 200 OK Content-Length: 4784 Content-Type: application/javascript | clean |
http://study-tour.ru/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: application/javascript | clean |
http://study-tour.ru/templates/mystudycamp/jquery.js | 200 OK Content-Length: 85558 Content-Type: application/javascript | clean |
http://study-tour.ru/templates/mystudycamp/script.js | 200 OK Content-Length: 7486 Content-Type: application/javascript | clean |
http://study-tour.ru/templates/mystudycamp/swfobject.js | 200 OK Content-Length: 10235 Content-Type: application/javascript | clean |
http://study-tour.ru/index.php?option=com_content&view=featured&Itemid=101 | 200 OK Content-Length: 8185 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.studycamp.ru ...[3013 bytes skipped]... gt; <div class="art-post-body"> <div class="art-post-inner"> <div class="art-postcontent"> 1<div class="art-article"><p>ÐÑ Ð½Ð°Ñ Ð¾Ð´Ð¸ÑеÑÑ <nobr>на ÑÐµÑ Ð½Ð¾Ð»Ð¾Ð³Ð¸ÑеÑком</nobr> ÑайÑе, <nobr>а длÑ</nobr> полноÑенной ÑабоÑÑ Ð¿ÐµÑейдиÑе пожалÑйÑÑа <nobr>на ÑайÑ</nobr> <a href="http://www.studycamp.ru"><span style="font-size: 12pt;">www.studycamp.ru</span></a> (лагеÑÑ) или <a href="http://www.study-centre.ru"><span style="font-size: 12pt;"><nobr>www.study-centre.ru</nobr></span></a> (обÑÑение <nobr>за ÑÑбежом)</nobr></p></div> </div> <div class="cleared"></div> </div> <div class="cleared"></div> </ ...[1212 bytes skipped]... | ||
http://study-tour.ru/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=study-tour.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://study-tour.ru/
Result: study-tour.ru is not infected or malware details are not published yet.
Result: study-tour.ru is not infected or malware details are not published yet.