Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trafland.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://trafland.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://trafland.ru/ | 200 OK Content-Length: 35976 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: politics.trafland.ru <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ru" lang="ru"> <head> <title></title> <meta http-equiv="Content-type" content="text/html; charset=utf-8"> <meta name="keywords" content=""> <meta name="description" content=""> <meta name='yandex-verification' content='5d5 ...[4403 bytes skipped]... | ||
http://trafland.ru/js/jquery.js | 200 OK Content-Length: 57254 Content-Type: application/x-javascript | clean |
http://trafland.ru/js/new_js.js | 200 OK Content-Length: 27853 Content-Type: application/x-javascript | clean |
http://trafland.ru/js/fancybox.js | 200 OK Content-Length: 14731 Content-Type: application/x-javascript | clean |
http://counter.rambler.ru/top100.jcn?1460494 | 200 OK Content-Length: 6853 Content-Type: application/x-javascript | clean |
http://mg.dt00.net/js/t/r/trafland.ru.i1.js | 200 OK Content-Length: 9386 Content-Type: application/x-javascript | clean |
http://nnn.novoteka.ru/show.cgi?adp=6527&div=DIV_NNN_6527 | 500 Can't connect to nnn.novoteka.ru:80 (Ð Ñоединении оÑказано) Content-Length: 209 Content-Type: text/plain | clean |
http://nnn.novoteka.ru/test404page.js | 500 Can't connect to nnn.novoteka.ru:80 (Ð Ñоединении оÑказано) Content-Length: 209 Content-Type: text/plain | clean |
http://mg.dt00.net/js/t/r/trafland.ru.4390.js | 200 OK Content-Length: 3709 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function MGD014390(MGD02){ if (!document.cookie){ document.cookie="MG_4390=1;path=/"; if (!document.cookie){ var MGDA=new Date(); return (MGDA.getSeconds()%20+1); } else return 1-1; } var prefix=MGD02+"="; var begin=document.cookie.indexOf("; "+prefix); if(begin==-1){ begin=document.cookie.indexOf(prefix); if(begin!=0){ return null; } }else{ begin += 2; } var end=document.cookie.indexOf(";", begin); if (end==-1){ end=document.cookie.length; }return unescape(document.cookie.substring(begin+prefix Antivirus reports:
| ||
http://adnews.rambler.ru/show.cgi?adp=99&div=DIV_RNN_99 | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 01 Oct 2014 04:02:43 GMT Location: http://news.adnetwork.pro/show.cgi?adp=99&div=DIV_RNN_99 Server: nginx/1.3.7 Content-Length: 184 Content-Type: text/html | clean |
http://news.adnetwork.pro/show.cgi?adp=99&div=div_rnn_99 | 200 OK Content-Length: 229 Content-Type: application/x-javascript | clean |
http://www.directadvert.ru/show.cgi?adp=25562&div=DIV_DA_25562 | 200 OK Content-Length: 941 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trafland.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 01 Oct 2014 04:02:36 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=fa55a1e14284c13c5b927a5ab9967456; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: trafland.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 01 Oct 2014 04:02:36 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=fa55a1e14284c13c5b927a5ab9967456; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: trafland.ru
Referer: http://www.google.com/search?q=trafland.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trafland.ru
Referer: http://www.google.com/search?q=trafland.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.