Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=wayofpower.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: wayofpower.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 17 Sep 2014 22:48:28 GMT
Pragma: no-cache
Server: Jino.ru/mod_pizza
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified: Wed, 17 Sep 2014 16:48:28 +0400 GMT
Set-Cookie: PHPSESSID=7575a635fa7fffbd7d72cd65e7dd5d09; path=/
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
GET / HTTP/1.1
Host: wayofpower.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 17 Sep 2014 22:48:28 GMT
Pragma: no-cache
Server: Jino.ru/mod_pizza
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified: Wed, 17 Sep 2014 16:48:28 +0400 GMT
Set-Cookie: PHPSESSID=7575a635fa7fffbd7d72cd65e7dd5d09; path=/
Set-Cookie: dle_user_id=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
Set-Cookie: dle_password=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
Set-Cookie: dle_hash=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.wayofpower.ru; httponly
Second query (visit from search engine):
GET / HTTP/1.1
Host: wayofpower.ru
Referer: http://www.google.com/search?q=wayofpower.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: wayofpower.ru
Referer: http://www.google.com/search?q=wayofpower.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://wayofpower.ru/ | 200 OK Content-Length: 41002 Content-Type: text/html | clean |
http://counter.rambler.ru/top100.jcn?1992856 | 200 OK Content-Length: 6853 Content-Type: application/x-javascript | clean |
http://dwl.name/r.php?l=http://dwl.name/go.php?sid=2 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://dwl.name/test404page.js | HTTP/1.1 302 Found Cache-Control: max-age=3600 Connection: close Date: Wed, 17 Sep 2014 22:46:27 GMT Location: http://google.com/ Server: nginx/1.0.15 Content-Length: 276 Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 17 Sep 2014 23:46:27 GMT | clean |
http://google.com/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Wed, 17 Sep 2014 22:48:29 GMT Location: http://www.google.lt/?gws_rd=cr&ei=vQ8aVO2dEKWaygPttID4AQ Server: gws Content-Length: 258 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.002 P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." Set-Cookie: PREF=ID=11dc48093f4c8aba:FF=0:TM=1410994109:LM=1410994109:S=2G1JbBYZuPX1Y3w4; expires=Fri, 16-Sep-2016 22:48:29 GMT; path=/; domain=.google.com Set-Cookie: NID=67=C329cM1fSWVmCwmVuCCcSblzBXIkVXgH6Sl_QJyW10HP70ebg_9jEOHWoAGyx1Mk_x6r0zE8p1FMEnzJ7zp989i5G7egJCs7YJK1y5WYZvv_1HLHjIus-WcOwTi_89xK; expires=Thu, 19-Mar-2015 22:48:29 GMT; path=/; domain=.google.com; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/?gws_rd=cr&ei=vq8avo2dekwaygpttid4aq | 200 OK Content-Length: 52505 Content-Type: text/html | clean |
https://www.google.lt/webhp?tab=ww | 200 OK Content-Length: 64571 Content-Type: text/html | clean |
https://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 58311 Content-Type: text/html | clean |
https://www.google.lt/webhp?hl=lt&tab=iw | 200 OK Content-Length: 64633 Content-Type: text/html | clean |
http://www.google.lt/intl/lt/options/ | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=2592000 Connection: close Date: Wed, 17 Sep 2014 22:48:32 GMT Location: http://www.google.lt/intl/lt/about/products/ Server: sffe Content-Length: 241 Content-Type: text/html; charset=UTF-8 Expires: Fri, 17 Oct 2014 22:48:32 GMT Alternate-Protocol: 80:quic,p=0.002 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/intl/lt/about/products/ | 200 OK Content-Length: 7068 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/js/gweb/analytics/autotrack.js/ | 404 Not Found Content-Length: 1471 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt/preferences?hl=lt | 200 OK Content-Length: 63760 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 52304 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=ii | 200 OK Content-Length: 52276 Content-Type: text/html | clean |
http://www.google.lt/history/optout?hl=lt | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Wed, 17 Sep 2014 22:48:34 GMT Location: https://history.google.com/history/optout?hl=lt Server: Search-History HTTP Server Content-Length: 244 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.002 Set-Cookie: PREF=ID=f01c723e23b9cc48:TM=1410994114:LM=1410994114:S=dTEPDuiITDD3VG_s; expires=Fri, 16-Sep-2016 22:48:34 GMT; path=/; domain=.google.lt X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://history.google.com/history/optout?hl=lt | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Wed, 17 Sep 2014 22:48:34 GMT Location: http://www.google.com/ Server: Search-History HTTP Server Content-Length: 219 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 443:quic,p=0.002 Set-Cookie: PREF=ID=853f94a9480867d4:TM=1410994114:LM=1410994114:S=sZ49d_nz3TXBV5FY; expires=Fri, 16-Sep-2016 22:48:34 GMT; path=/; domain=.google.com X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.com/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Wed, 17 Sep 2014 22:48:34 GMT Location: http://www.google.lt/?gws_rd=cr&ei=wg8aVLXXJ8b_ygOGwYCgBA Server: gws Content-Length: 258 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.002 P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." Set-Cookie: PREF=ID=e45c0be9b7d9ad4c:FF=0:TM=1410994114:LM=1410994114:S=V9DDlr92P8qMYdwc; expires=Fri, 16-Sep-2016 22:48:34 GMT; path=/; domain=.google.com Set-Cookie: NID=67=MESukly5GzcPqUoCO5Zql3E8AGSmBhCWG5epR9RqOqL64ex8DiTQ24gmrktIbrXzoI-65hqZ944PpSo8jVJCgsNGlQIrmGJTyveUEewJgRKxv7bSIyp-vYn1yO_PbsrD; expires=Thu, 19-Mar-2015 22:48:34 GMT; path=/; domain=.google.com; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/?gws_rd=cr&ei=wg8avlxxj8b_ygogwycgba | 200 OK Content-Length: 52276 Content-Type: text/html | clean |