Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://temaphoto.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: temaphoto.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sun, 27 Apr 2014 10:48:23 GMT Location: http://goo.gl/0rXySb Server: nginx Content-Length: 282 Content-Type: text/html; charset=iso-8859-1 | malicious |
URL: http://goo.gl/0rXySb (imitation of visitor from search engine) GET /0rXySb HTTP/1.1 Host: goo.gl Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Sun, 27 Apr 2014 10:47:22 GMT Pragma: no-cache Age: 56 Location: http://sh.oowoo.ru/redsh.php Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Mon, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 80:quic X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | malicious |
URL: http://sh.oowoo.ru/redsh.php (imitation of visitor from search engine) GET /redsh.php HTTP/1.1 Host: sh.oowoo.ru Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Found Connection: close Date: Sun, 27 Apr 2014 10:43:23 GMT Location: http://targetnow.biz/?code=i8mjo7 Server: nginx/1.1.10 Content-Length: 0 Content-Type: text/html; charset=cp1251 X-Powered-By: PHP/5.2.17 | suspicious |
URL: http://targetnow.biz/?code=i8mjo7 (imitation of visitor from search engine) GET /?code=i8mjo7 HTTP/1.1 Host: targetnow.biz Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Found Connection: close Date: Sun, 27 Apr 2014 10:48:19 GMT Location: http://spinyla2.org/bux-systems_com/main.php?s=36984&c=2v&security_hash=ee69245f839c654bd774169968184a37 Server: nginx/1.4.3 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.5.1-1~dotdeb.1 X-Robots-Tag: noindex, nofollow, none, noarchive | suspicious |
Scanned pages/files
Request | Server response | Status |
http://temaphoto.ru/ | 200 OK Content-Length: 45747 Content-Type: text/html | clean |
http://temaphoto.ru/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ajax.js?ver=3.8.3 | 200 OK Content-Length: 33 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/persist.js?ver=3.8.3 | 200 OK Content-Length: 24995 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/store.js?ver=3.8.3 | 200 OK Content-Length: 5337 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ngg_store.js?ver=3.8.3 | 200 OK Content-Length: 894 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/jj-nextgen-jquery-slider/script/jquery.nivo.slider.pack.js?ver=2.4 | 200 OK Content-Length: 15919 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/jj-nextgen-jquery-slider/script/jquery.jj_ngg_shuffle.js?ver=3.8.3 | 200 OK Content-Length: 405 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/jj-nextgen-jquery-slider/script/jjnggutils.js?ver=3.8.3 | 200 OK Content-Length: 757 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/usernoise/js/usernoise.js?ver=3.7.12 | 200 OK Content-Length: 7814 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/usernoise/js/button.js?ver=3.7.12 | 200 OK Content-Length: 1493 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/wpfancybox/fancybox/jquery.fancybox-1.2.1.pack.js?ver=3.8.3 | 200 OK Content-Length: 8303 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/wpfancybox/fancybox/jquery.easing.1.3.js?ver=3.8.3 | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://temaphoto.ru/wp-content/plugins/vkontakte-api/js/callback.js?ver=3.8.3 | 200 OK Content-Length: 4754 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=temaphoto.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://temaphoto.ru/
Result: temaphoto.ru is not infected or malware details are not published yet.
Result: temaphoto.ru is not infected or malware details are not published yet.