Scanned pages/files
Request | Server response | Status |
http://www.19368.com/ | HTTP/1.1 200 OK Connection: close Date: Mon, 23 Jun 2014 22:04:43 GMT Accept-Ranges: bytes ETag: "10b34fba4c8dcf1:6ea" Server: Microsoft-IIS/6.0 Content-Length: 2447 Content-Location: http://www.19368.com/index.html Content-Type: text/html Last-Modified: Sat, 21 Jun 2014 12:31:29 GMT X-Powered-By: ASP.NET | clean |
http://www.19368.com/index.html | 200 OK Content-Length: 2447 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: .:: Hacked by Masih-Team Security Team (Masih-Team.Ir) ::. | <html><head> <!-- saved from url=(0039)http://www.ashiyane.ir/project/ash.htm --><title>.:: Hacked by Masih-Team Security Team (Masih-Team.Ir) ::. |</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <style type="text/css">BODY { BACKGROUND-COLOR: #000000 } .style2 { FONT-SIZE: 20px; COLOR: #ffffff; FONT-FAMILY: Geneva, Arial, Helvetica, sans-serif } .style3 { COLOR: #ff0000 } .style4 { COLOR: #ff7f50 } .style5 { COLOR: #ffffff } ...[2629 bytes skipped]... | ||
http://www.19368.com/test404page.js | 200 OK Content-Length: 8595 Content-Type: text/html | clean |
http://www.19368.com/common.js | 200 OK Content-Length: 173 Content-Type: application/x-javascript | clean |
http://js.users.51.la/16931900.js | 200 OK Content-Length: 1980 Content-Type: application/x-javascript | clean |
http://www.19368.com/a/hot/ | 200 OK Content-Length: 8366 Content-Type: text/html | clean |
http://www.19368.com/a/product/ | 200 OK Content-Length: 8468 Content-Type: text/html | clean |
http://www.19368.com/a/news/ | 200 OK Content-Length: 8603 Content-Type: text/html | clean |
http://www.19368.com/a/cnews/ | 200 OK Content-Length: 8568 Content-Type: text/html | clean |
http://www.19368.com/a/focus/ | 200 OK Content-Length: 8471 Content-Type: text/html | clean |
http://www.19368.com/sitemap.html | 200 OK Content-Length: 5604 Content-Type: text/html | clean |
http://www.19368.com/tj.js | 200 OK Content-Length: 122 Content-Type: application/x-javascript | clean |
http://www.19368.com/sitemap_340.html | 200 OK Content-Length: 5704 Content-Type: text/html | clean |
http://www.19368.com/sitemap_740.html | 200 OK Content-Length: 5575 Content-Type: text/html | clean |
http://www.19368.com/sitemap_78.html | 200 OK Content-Length: 5643 Content-Type: text/html | clean |
http://www.19368.com/sitemap_646.html | 200 OK Content-Length: 5675 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 19368.com
Result:
GET / HTTP/1.1
Host: 19368.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 19368.com
Referer: http://www.google.com/search?q=19368.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 19368.com
Referer: http://www.google.com/search?q=19368.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=19368.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://19368.com/
Result: 19368.com is not infected or malware details are not published yet.
Result: 19368.com is not infected or malware details are not published yet.