Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tvoyagalaktika.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.tvoyagalaktika.ru/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 11 Sep 2014 03:36:29 GMT Pragma: no-cache Location: http://tvoyagalaktika.ru/ Server: nginx/1.6.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=acc91de474712da709f3f271b1af293b; path=/ Set-Cookie: wfvt_3705800675=541118bce5ef2; expires=Thu, 11-Sep-2014 04:06:28 GMT; path=/ X-Pingback: http://tvoyagalaktika.ru/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://tvoyagalaktika.ru/ | 200 OK Content-Length: 83700 Content-Type: text/html | suspicious |
Suspicious code found <ul class="nostyle" style="float:left">
<li><div> <a rel="nofollow" target="_blank" class="mrc__plugin_uber_like_button" href="http%3A%2F%2Ftvoyagalaktika.ru%2F" data-mrc-config="{'type' : 'button', 'caption-mm' : '2', 'caption-ok' : '1', 'counter' : 'true', 'text' : 'true', 'width' : '250px', 'show_faces': '1', 'show_text': '1'}">ÐÑавиÑÑÑ</a> </div></li> <li> pageUrl: 'http://tvoyagalaktika.ru/', pageImage: 'http://tvoyagalaktika.ru/wp-content/uploads/2011/02/tvoyagalaktika-copy.jpg', text: '© ХÑдожеÑÑÐ²ÐµÐ½Ð½Ð°Ñ ÑоÑпиÑÑ Ð¿Ð¾Ñолков и ÑÑен в ÑÑиле ÑаÑÑÑÑего звÑздного неба, коÑоÑое ÑвеÑиÑÑÑ Ð² ÑемноÑе! // < ![CDATA[ // < ![CDATA[ // < ![' }, 289); --> </script></ul> | ||
http://userapi.com/js/api/openapi.js | 200 OK Content-Length: 64013 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/swfobject/2.2/swfobject.js?ver=2.2 | 200 OK Content-Length: 10220 Content-Type: text/javascript | clean |
http://userapi.com/js/api/openapi.js?ver=3.9.1 | 200 OK Content-Length: 64013 Content-Type: application/x-javascript | clean |
http://tvoyagalaktika.ru/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/x-javascript | clean |
http://tvoyagalaktika.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://tvoyagalaktika.ru/wp-content/plugins/vkontakte-api/js/callback.js?ver=3.9.1 | 200 OK Content-Length: 5068 Content-Type: application/x-javascript | clean |
http://vk.com/js/api/share.js?ver=3.9.1 | 200 OK Content-Length: 10156 Content-Type: application/x-javascript | clean |
https://apis.google.com/js/plusone.js?ver=3.9.1 | 200 OK Content-Length: 12403 Content-Type: application/javascript | clean |
http://tvoyagalaktika.ru/wp-content/plugins/cforms/js/cforms.js | 200 OK Content-Length: 17819 Content-Type: application/x-javascript | clean |
http://tvoyagalaktika.ru/wp-content/uploads/2013/04/swfobject.2.3.js | 200 OK Content-Length: 10220 Content-Type: application/x-javascript | clean |
http://www.tvoyagalaktika.ru//vk.com/js/api/openapi.js?97/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Thu, 11 Sep 2014 03:36:32 GMT Pragma: no-cache Location: http://tvoyagalaktika.ru/vk.com/js/api/openapi.js?97/ Server: nginx/1.6.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=6965a3b518cef66b36597cf333cc69a9; path=/ Set-Cookie: wfvt_3705800675=541118c088297; expires=Thu, 11-Sep-2014 04:06:32 GMT; path=/ X-Pingback: http://tvoyagalaktika.ru/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://tvoyagalaktika.ru/vk.com/js/api/openapi.js?97/ | 404 Not Found Content-Length: 83321 Content-Type: text/html | suspicious |
Suspicious code found <ul class="nostyle" style="float:left">
<li><div> <a rel="nofollow" target="_blank" class="mrc__plugin_uber_like_button" href="http%3A%2F%2Ftvoyagalaktika.ru%2Farchives%2F1046%2F" data-mrc-config="{'type' : 'button', 'caption-mm' : '2', 'caption-ok' : '1', 'counter' : 'true', 'text' : 'true', 'width' : '250px', 'show_faces': '1', 'show_text': '1'}">ÐÑавиÑÑÑ</a> </div></li> VK.Widgets.Like('vkapi_like_1046', { width: 1, height: 20, type: 'mini', verb: '0', pageTitle: '', pageDescription: '', pageUrl: 'http://tvoyagalaktika.ru/archives/1046/', pageImage: '', text: 'ÐвÑздное небо на поÑолок http://tvoyagalaktika.ru/?p=1046' }, 1046); --> </script></ul> | ||
http://tvoyagalaktika.ru//vk.com/js/api/openapi.js?97/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Thu, 11 Sep 2014 03:36:33 GMT Pragma: no-cache Location: http://tvoyagalaktika.ru/vk.com/js/api/openapi.js?97/ Server: nginx/1.6.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=f091d179d463acddd52d7156dbf67807; path=/ Set-Cookie: wfvt_3705800675=541118c1c2bcf; expires=Thu, 11-Sep-2014 04:06:33 GMT; path=/ X-Pingback: http://tvoyagalaktika.ru/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://tvoyagalaktika.ru/test404page.js | 404 Not Found Content-Length: 83293 Content-Type: text/html | suspicious |
Suspicious code found <ul class="nostyle" style="float:left">
<li><div> <a rel="nofollow" target="_blank" class="mrc__plugin_uber_like_button" href="http%3A%2F%2Ftvoyagalaktika.ru%2Farchives%2F1046%2F" data-mrc-config="{'type' : 'button', 'caption-mm' : '2', 'caption-ok' : '1', 'counter' : 'true', 'text' : 'true', 'width' : '250px', 'show_faces': '1', 'show_text': '1'}">ÐÑавиÑÑÑ</a> </div></li> VK.Widgets.Like('vkapi_like_1046', { width: 1, height: 20, type: 'mini', verb: '0', pageTitle: '', pageDescription: '', pageUrl: 'http://tvoyagalaktika.ru/archives/1046/', pageImage: '', text: 'ÐвÑздное небо на поÑолок http://tvoyagalaktika.ru/?p=1046' }, 1046); --> </script></ul> | ||
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21347 Content-Type: text/javascript | clean |
http://tvoyagalaktika.ru/wp-content/plugins/rps-image-gallery/dependencies/fancybox/jquery.easing-1.3.pack.js?ver=1.0.0 | 200 OK Content-Length: 6717 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tvoyagalaktika.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 11 Sep 2014 03:36:29 GMT
Pragma: no-cache
Server: nginx/1.6.0
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://tvoyagalaktika.ru/>; rel=shortlink
Set-Cookie: PHPSESSID=c012d5784c50d39da24619f632f29ba5; path=/
Set-Cookie: wfvt_3705800675=541118bd44cf2; expires=Thu, 11-Sep-2014 04:06:29 GMT; path=/
X-Pingback: http://tvoyagalaktika.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: tvoyagalaktika.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Thu, 11 Sep 2014 03:36:29 GMT
Pragma: no-cache
Server: nginx/1.6.0
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://tvoyagalaktika.ru/>; rel=shortlink
Set-Cookie: PHPSESSID=c012d5784c50d39da24619f632f29ba5; path=/
Set-Cookie: wfvt_3705800675=541118bd44cf2; expires=Thu, 11-Sep-2014 04:06:29 GMT; path=/
X-Pingback: http://tvoyagalaktika.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: tvoyagalaktika.ru
Referer: http://www.google.com/search?q=tvoyagalaktika.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tvoyagalaktika.ru
Referer: http://www.google.com/search?q=tvoyagalaktika.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.