Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zhane.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://zhane.ru/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://zhane.ru/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: zhane.ru Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Tue, 24 Jun 2014 01:18:10 GMT Location: http://alfsystem.com.my/includes/domit/1.php Server: nginx/1.4.7 Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.27 | malicious |
URL: http://alfsystem.com.my/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: alfsystem.com.my Referer: http://www.google.com/search?q=redirect+check2 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 24 Jun 2014 01:18:10 GMT Location: http://www.csra.de/includes/domit/1.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.3.23 | malicious |
URL: http://www.csra.de/includes/domit/1.php (imitation of visitor from search engine) GET /includes/domit/1.php HTTP/1.1 Host: www.csra.de Referer: http://www.google.com/search?q=redirect+check3 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 24 Jun 2014 01:18:11 GMT Location: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.4.29 | malicious |
URL: http://jbtconsultinggroup.com/components/com_user/views/login/tmpl/1/all3.php (imitation of visitor from search engine) GET /components/com_user/views/login/tmpl/1/all3.php HTTP/1.1 Host: jbtconsultinggroup.com Referer: http://www.google.com/search?q=redirect+check4 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 24 Jun 2014 01:18:11 GMT Location: http://google.ru Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | malicious |
Scanned pages/files
Request | Server response | Status |
http://zhane.ru/ | 200 OK Content-Length: 36519 Content-Type: text/html | suspicious |
Suspicious code found <div class="footer_wrap"> <div id="footer"> <div class="copy"><div style="text-align: center;">© 2008-2014. ÐÑавовÑе аÑпекÑÑ ÑнеÑгоÑнабжениÑ</div> <div style="text-align: center;">ХоÑÑинг Ð¾Ñ <a href="http://1001host.ru/">1001host</a></div></div> <b class="crn bl"><i> </i></b> <b class="crn br"><i>      }); })(window, "yandex_metrika_callbacks"); </script></div> <script src="//mc.yandex.ru/metrika/watch.js" type="text/javascript" defer="defer"></script> <noscript><div><img src="//mc.yandex.ru/watch/12478813" style="position:absolute; left:-9999px;" alt="" /></div></noscript> <!-- /Yandex.Metrika counter --> </div> </div> | ||
http://zhane.ru/media/system/js/caption.js | 200 OK Content-Length: 2011 Content-Type: application/x-javascript | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js | 200 OK Content-Length: 78601 Content-Type: text/javascript | clean |
http://zhane.ru/templates/zhane_des/js/jqueryslidemenu.js | 200 OK Content-Length: 2593 Content-Type: application/x-javascript | clean |
http://userapi.com/js/api/openapi.js?48 | 200 OK Content-Length: 64039 Content-Type: application/x-javascript | clean |
http://zhane.ru/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |