Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zakupydodomu.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://zakupydodomu.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://zakupydodomu.com/ | HTTP/1.1 302 Found Cache-Control: private Date: Sat, 04 Oct 2014 16:57:44 GMT Location: http://www.hugedomains.com/domain_profile.cfm?d=zakupydodomu&e=com Server: Microsoft-IIS/8.0 Content-Length: 187 Content-Type: text/html; charset=utf-8 X-Powered-By: ASP.NET | clean |
http://www.hugedomains.com/domain_profile.cfm?d=zakupydodomu&e=com | 200 OK Content-Length: 12983 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: 3dwww.zakupydodomu.com var chost= ((document.location.protocol=="https:") ? "https://" : "http://"); document.write("<img height=1 width=1 border=0 src='" + chost + "static.hugedomains.com/Metrics/stat.aspx?r="+Math.floor(Math.random()*5000)+"&s=w29&u=" +escape(window.location.href) + "&rf=http%3A%2F%2Fyandex.ru%2Fyandsearch%3Ftext%3dwww.zakupydodomu.com%26lr%3D213' />"); Decoded script: <img height=1 width=1 border=0 src='http://static.hugedomains.com/Metrics/stat.aspx?r=2901&s=w29&u=http%3A//example.com&rf=http%3A%2F%2Fyandex.ru%2Fyandsearch%3Ftext%3dwww.zakupydodomu.com%26lr%3D213' /> | ||
http://static.HugeDomains.com/js/common.js?d=2012-02-06 | 200 OK Content-Length: 6727 Content-Type: application/x-javascript | clean |
http://zakupydodomu.com//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit/ | HTTP/1.1 302 Found Cache-Control: private Date: Sat, 04 Oct 2014 16:57:46 GMT Location: http://www.hugedomains.com/domain_profile.cfm?d=zakupydodomu&e=com Server: Microsoft-IIS/8.0 Content-Length: 187 Content-Type: text/html; charset=utf-8 X-Powered-By: ASP.NET | clean |
http://www.hugedomains.com/test404page.js | HTTP/1.1 302 Found Cache-Control: private Date: Sat, 04 Oct 2014 16:57:27 GMT Location: http://www.HugeDomains.com/ Server: Microsoft-IIS/8.5 Content-Length: 193 Content-Location: http://www.HugeDomains.com/ Content-Type: text/html; charset=utf-8 Set-Cookie: BTP=1; expires=Sun, 04-Oct-15 16:57:25 GMT; domain=hugedomains.com; path=/ Set-Cookie: CFID=1040819; expires=Mon, 02-Oct-23 16:57:25 GMT; path=/; HttpOnly Set-Cookie: CFTOKEN=DB5D43EC-520C-4F54-94DCB7E6592E24C1; expires=Mon, 02-Oct-23 16:57:25 GMT; path=/; HttpOnly Set-Cookie: SHOPPINGCART=; expires=Mon, 03-Nov-14 16:57:25 GMT; path=/ Set-Cookie: REFLOC=; expires=Sun, 04-Oct-15 16:57:25 GMT; path=/ Set-Cookie: HD=127E07CF197A40EA87D482BFCA73EBA0014; expires=Sun, 04-Oct-15 16:57:25 GMT; path=/ Set-Cookie: FWO=vQIF2KwBCfaKGgX1oBAW6PgJWK74QUev%2BVhaqrVEFuW9Bkq5%2B0VbquREWrP5QUqv%2BU9fqfNHX7m0CVus%2FjBaqYozW6f%2BNF6ujDRSqY1BUqyLMynf%2FkYv3IhFWq%2F9; expires=Sun, 04-Oct-15 16:57:25 GMT; path=/ Set-Cookie: PV=%2BAka%2F64QPPesAhk%3D; expires=Sun, 04-Oct-15 16:57:25 GMT; path=/ X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | clean |
http://www.hugedomains.com/ | HTTP/1.1 200 OK Cache-Control: private Date: Sat, 04 Oct 2014 16:57:28 GMT Accept-Ranges: bytes ETag: W/"eef388bff3dfcf1:3591" Server: Microsoft-IIS/8.5 Content-Length: 22361 Content-Location: http://www.hugedomains.com/index.htm Content-Type: text/html; charset=utf-8 Last-Modified: Sat, 04 Oct 2014 16:53:40 GMT X-Powered-By: ASP.NET | clean |
http://www.hugedomains.com/index.htm | 200 OK Content-Length: 22455 Content-Type: text/html | clean |
http://www.statcounter.com/counter/counter_xhtml.js | 200 OK Content-Length: 15530 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: zakupydodomu.com
Result:
HTTP/1.1 302 Found
Cache-Control: private
Date: Sat, 04 Oct 2014 16:57:44 GMT
Location: http://www.hugedomains.com/domain_profile.cfm?d=zakupydodomu&e=com
Server: Microsoft-IIS/8.0
Content-Length: 187
Content-Type: text/html; charset=utf-8
X-Powered-By: ASP.NET
...187 bytes of data.
GET / HTTP/1.1
Host: zakupydodomu.com
Result:
HTTP/1.1 302 Found
Cache-Control: private
Date: Sat, 04 Oct 2014 16:57:44 GMT
Location: http://www.hugedomains.com/domain_profile.cfm?d=zakupydodomu&e=com
Server: Microsoft-IIS/8.0
Content-Length: 187
Content-Type: text/html; charset=utf-8
X-Powered-By: ASP.NET
...187 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: zakupydodomu.com
Referer: http://www.google.com/search?q=zakupydodomu.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: zakupydodomu.com
Referer: http://www.google.com/search?q=zakupydodomu.com
Result:
The result is similar to the first query. There are no suspicious redirects found.