Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zen-it.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://zen-it.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://zen-it.ru/ | 200 OK Content-Length: 6048 Content-Type: text/html | clean |
http://zen-it.ru/main_res/js_jquery/jquery.js | 200 OK Content-Length: 75052 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(A,w){function ma(){if(!c.isReady){try{s.documentElement.doScroll("left")}catch(a){setTimeout(ma,1);return}c.ready()}}function Qa(a,b){b.src?c.ajax({url:b.src,async:false,dataType:"script"}):c.globalEval(b.text||b.textContent||b.innerHTML||"");b.parentNode&&b.parentNode.removeChild(b)}function X(a,b,d,f,e,j){var i=a.length;if(typeof b==="object"){for(var o in b)X(a,o,b[o],f,e,d);return a}if(d!==w){f=!j&&f&&c.isFunction(d);for(o=0;o<i;o++)e(a[o],b,f?d.call(a[o] Antivirus reports:
| ||
http://zen-it.ru/main_res/js_swfobject/swfobject.js | 200 OK Content-Length: 9758 Content-Type: application/x-javascript | clean |
http://zen-it.ru/main_res/js/main.js | 200 OK Content-Length: 5836 Content-Type: application/x-javascript | clean |
http://zen-it.ru/services/ | 200 OK Content-Length: 2672 Content-Type: text/html | clean |
http://zen-it.ru/solutions/ | 200 OK Content-Length: 2678 Content-Type: text/html | clean |
http://zen-it.ru/contacts/ | 200 OK Content-Length: 2465 Content-Type: text/html | clean |
http://zen-it.ru/test404page.js | 404 Not Found Content-Length: 351 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: zen-it.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 08 Mar 2015 14:45:11 GMT
Pragma: no-cache
Server: DataPalm/3.5
Content-Length: 6048
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b8e046ffa587b9a0836c10113c1425f7; path=/
...6048 bytes of data.
GET / HTTP/1.1
Host: zen-it.ru
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 08 Mar 2015 14:45:11 GMT
Pragma: no-cache
Server: DataPalm/3.5
Content-Length: 6048
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b8e046ffa587b9a0836c10113c1425f7; path=/
...6048 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: zen-it.ru
Referer: http://www.google.com/search?q=zen-it.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: zen-it.ru
Referer: http://www.google.com/search?q=zen-it.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.