Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trekit.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://trekit.ru/ | 200 OK Content-Length: 35963 Content-Type: text/html | clean |
http://trekit.ru/includes/jquery/jquery.js | 200 OK Content-Length: 55715 Content-Type: application/javascript | clean |
http://trekit.ru/core/js/common.js | 200 OK Content-Length: 234 Content-Type: application/javascript | clean |
http://trekit.ru/templates/_default_/js/swfobject.js | 200 OK Content-Length: 43413 Content-Type: application/javascript | clean |
http://trekit.ru/templates/_default_/js/coin-slider.min.js | 200 OK Content-Length: 8443 Content-Type: application/javascript | clean |
http://trekit.ru/templates/_default_/js/jquery.tabSlideOut.v1.3.js | 200 OK Content-Length: 7293 Content-Type: application/javascript | clean |
http://mc.yandex.ru/metrika/watch.js | 200 OK Content-Length: 59779 Content-Type: application/x-javascript | clean |
http://trekit.ru/modules/mod_latest/js/latest.js | 200 OK Content-Length: 194 Content-Type: application/javascript | clean |
http://trekit.ru/index.html | 200 OK Content-Length: 35963 Content-Type: text/html | clean |
http://trekit.ru/obsluzhivanie-i-remont-avtomobilei-mercedes.html | 200 OK Content-Length: 36517 Content-Type: text/html | clean |
http://trekit.ru/core/js/karma.js | 200 OK Content-Length: 496 Content-Type: application/javascript | clean |
http://trekit.ru//mc.yandex.ru/metrika/watch.js/ | 200 OK Content-Length: 54576 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(e,c,oa){function P(b,g){return function(){try{return b.apply(this,arguments)}catch(c){var e=["cp: "+g,c.name+": "+c.message,"debug: "+xa,"stack: "+c.stack];(new Image).src="//an.yandex.ru/jserr/"+counterId+"?"+$({"cnt-class":100+counterType,errmsg:e.join("; ").replace(/\r?\n/g,"\\n")})}}}function S(b,g,c){return e.setTimeout(P(b,c||"setTimeout"),g)}function M(b){for(var g=1,c=b.length;g<arguments.length;g++)b[c++]=arguments[g];return b.length}function pa(b){return"[object Array]"==O qa();e.setAttribute("style","position:absolute;left:-9999px;width:1px;height:1px;overflow:hidden;visibility:hidden");b.appendChild(e);S(function(){b.removeChild(e)},1E4)},g=function(){e.removeEventListener("load",g,!1);b()},p=e.performance;qa(200)||Ya._metrika.isAd||(Ya._metrika.isAd=!0,"http:"==ma&&"object"==typeof p&&e.addEventListener&&(p.timing&&p.timing.loadEventStart?b():e.addEventListener("load",g,!1)))})()})(this,this.document); Antivirus reports:
| ||
http://trekit.ru/korporativnym-klientam.html | 200 OK Content-Length: 32797 Content-Type: text/html | clean |
http://trekit.ru/originalnye-i-neorginalnye-avtozapchasti-na-mersedes.html | 200 OK Content-Length: 33482 Content-Type: text/html | clean |
http://trekit.ru/prais-list-nashego-avtoservisa-mercedes.html | 200 OK Content-Length: 46714 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trekit.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Connection: close
Date: Thu, 02 Oct 2014 20:24:47 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Length: 35963
Content-Type: text/html;charset=windows-1251
Expires: Sat, 04 Oct 2014 00:00:00 GMT
Last-Modified: Wed, 01 Oct 2014 00:00:00 GMT
X-Powered-By: PHP/5.2.17
...35963 bytes of data.
GET / HTTP/1.1
Host: trekit.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Connection: close
Date: Thu, 02 Oct 2014 20:24:47 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Length: 35963
Content-Type: text/html;charset=windows-1251
Expires: Sat, 04 Oct 2014 00:00:00 GMT
Last-Modified: Wed, 01 Oct 2014 00:00:00 GMT
X-Powered-By: PHP/5.2.17
...35963 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: trekit.ru
Referer: http://www.google.com/search?q=trekit.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trekit.ru
Referer: http://www.google.com/search?q=trekit.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.