Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xfoto.su
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xfoto.su/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://xfoto.su/ | 200 OK Content-Length: 91639 Content-Type: text/html | clean |
http://v2mlyellow.com/?acc=20448&waponly=yes&zona=0&landing=xcust | 200 OK Content-Length: 114 Content-Type: text/html | clean |
http://v2mlyellow.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://xfoto.su/ajax/lib/JsHttpRequest/JsHttpRequest.js | 200 OK Content-Length: 13892 Content-Type: application/x-javascript | clean |
http://bestevernews.com/viewt.js | 200 OK Content-Length: 20987 Content-Type: application/x-javascript | clean |
http://v.visitweb.com/v/83870 | 200 OK Content-Length: 62976 Content-Type: text/javascript | clean |
http://v.visitweb.com/v/83875 | 200 OK Content-Length: 64164 Content-Type: text/javascript | clean |
http://www.xxx-news.su/user/1723/xfoto.su_inf_1.php | 200 OK Content-Length: 5690 Content-Type: text/html | clean |
http://www.xxx-news.su/go_slin.php?id=50236&sour=1723 | HTTP/1.1 302 Found Connection: close Date: Thu, 11 Sep 2014 02:18:33 GMT Location: /go_news.php?id=1723&news=50236&f= Server: nginx/1.1.19 Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.10-1ubuntu3.7 | clean |
http://www.xxx-news.su/go_news.php?id=1723&news=50236&f= | 200 OK Content-Length: 69735 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.powersex.ru <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1251" /> <title>Ñàìîå ïîïóëÿðíûå íîâîñòè - XXX-NEWS.Su</title> <script type="text/javascript" src="http://v2mlyellow.com/?acc=20448&waponly=yes&zona ...[4334 bytes skipped]... | ||
http://code.jquery.com/jquery-1.8.3.min.js | 200 OK Content-Length: 93636 Content-Type: application/x-javascript | clean |
http://herefegedef.net/viewt.js | 200 OK Content-Length: 20987 Content-Type: application/x-javascript | clean |
http://mopilod.com/static/tds.js | 200 OK Content-Length: 18750 Content-Type: application/javascript | clean |
http://www.xxx-news.su/ | 200 OK Content-Length: 36819 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.powersex.ru <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1251" /> <title>Âñå ñ åæåäíåâíûì îáíîâëåíèåì - XXX-NEWS.Su</title> <script type="text/javascript" src="http://v2mlyellow.com/?acc=20448&waponly=yes& ...[4334 bytes skipped]... | ||
http://www.xxx-news.su/index.php?informers=1 | 200 OK Content-Length: 22781 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.powersex.ru <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1251" /> <title>XXX-NEWS.Su</title> <script type="text/javascript" src="http://v2mlyellow.com/?acc=20448&waponly=yes&zona=0&landing=xcust">&l ...[4346 bytes skipped]... | ||
http://www.xxx-news.su/user/primer/primer_left_2.php | 200 OK Content-Length: 2410 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xfoto.su
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 02:20:24 GMT
Server: nginx/0.6.39
Content-Type: text/html; charset=cp1251
X-Powered-By: PHP/4.4.2
GET / HTTP/1.1
Host: xfoto.su
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 02:20:24 GMT
Server: nginx/0.6.39
Content-Type: text/html; charset=cp1251
X-Powered-By: PHP/4.4.2
Second query (visit from search engine):
GET / HTTP/1.1
Host: xfoto.su
Referer: http://www.google.com/search?q=xfoto.su
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xfoto.su
Referer: http://www.google.com/search?q=xfoto.su
Result:
The result is similar to the first query. There are no suspicious redirects found.