Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: turismvitalii.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 08:18:32 GMT
Pragma: no-cache
Server: nginx/1.4.1
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=h392k2euk0rndo7a580lulf0d3; path=/
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
X-Powered-By: PHP/5.3.26
GET / HTTP/1.1
Host: turismvitalii.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 08:18:32 GMT
Pragma: no-cache
Server: nginx/1.4.1
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=h392k2euk0rndo7a580lulf0d3; path=/
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.turismvitalii.ru; httponly
X-Powered-By: PHP/5.3.26
Second query (visit from search engine):
GET / HTTP/1.1
Host: turismvitalii.ru
Referer: http://www.google.com/search?q=turismvitalii.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: turismvitalii.ru
Referer: http://www.google.com/search?q=turismvitalii.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://turismvitalii.ru/ | 200 OK Content-Length: 44692 Content-Type: text/html | clean |
http://turismvitalii.ru/engine/classes/js/jquery.js | 200 OK Content-Length: 93868 Content-Type: application/x-javascript | clean |
http://turismvitalii.ru/engine/classes/js/jqueryui.js | 200 OK Content-Length: 65477 Content-Type: application/x-javascript | clean |
http://turismvitalii.ru/engine/classes/js/dle_js.js | 200 OK Content-Length: 20786 Content-Type: application/x-javascript | clean |
http://turismvitalii.ru/templates/Duplex/js/shareTT.js | 200 OK Content-Length: 3165 Content-Type: application/javascript | clean |
http://turismvitalii.ru/templates/Duplex/js/active.js | 200 OK Content-Length: 2436 Content-Type: application/javascript | clean |
http://turismvitalii.ru/templates/Duplex/js/jquery.carouFredSel-5.2.3-packed.js | 200 OK Content-Length: 29893 Content-Type: application/javascript | clean |
http://userapi.com/js/api/openapi.js?31 | 200 OK Content-Length: 64013 Content-Type: application/x-javascript | clean |
http://turismvitalii.ru/templates/Duplex/js/jquery.ttabs.js | 200 OK Content-Length: 1065 Content-Type: application/javascript | clean |
http://www.trivago.ru/ru/srv/destination/js/hotel_v1.js?path=31467&stats=&img=mx&style=disable | 200 OK Content-Length: 33459 Content-Type: text/javascript | clean |
http://turismvitalii.ru/about_cities/ | 200 OK Content-Length: 26883 Content-Type: text/html | clean |
http://turismvitalii.ru/shopping/ | 200 OK Content-Length: 26953 Content-Type: text/html | clean |
http://turismvitalii.ru/turism/ | 200 OK Content-Length: 27769 Content-Type: text/html | clean |
http://turismvitalii.ru/turism_news/ | 200 OK Content-Length: 27970 Content-Type: text/html | clean |
http://turismvitalii.ru/turism_news/266-nochnaya-ekskursiya-v-mertvyy-gorod-gerkulanum.html | 200 OK Content-Length: 22778 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=turismvitalii.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://turismvitalii.ru/
Result: turismvitalii.ru is not infected or malware details are not published yet.
Result: turismvitalii.ru is not infected or malware details are not published yet.