Scanned pages/files
Request | Server response | Status |
http://420authorization.com/ | 200 OK Content-Length: 2041 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By The Crows Crew ...[1046 bytes skipped]... 0px 5px #000000, 0px 0px 30px #000000, 0px 3px 50px #000000; } </style> </head> <center> <td align="center"> <br><br> <a href=http://thecrowscrew.org/ target="_blank"><img src='http://myminifile.com/images/1jgj.png'></a><br><br><br><br> <blink><font color="grey" size="5">Hacked By The Crows Crew</font></blink><br> <font color="grey" size="4">Just Test Your Security...</font><br> <br> <br> <font color="grey" size="4">MsconfiX | catalyst71 | ovanIsmycode | Gabby | Don Ojan | Fee_lizi0ust | Yz_byte | Dawedireng</font><br> <font color="grey" size="4">BeastarStealacar | 777r | kit4r0 | din_muh | adecakep7 | DendyIsMe | ph_outL4w | NO35 | Al3x.K ...[632 bytes skipped]... | ||
http://420authorization.com/test404page.js | 404 Not Found Content-Length: 11812 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/javascript | clean |
http://420authorization.com/cgi-sys/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 420authorization.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 28 Jun 2015 03:41:02 GMT
Server: nginx/1.8.0
Content-Type: text/html
GET / HTTP/1.1
Host: 420authorization.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 28 Jun 2015 03:41:02 GMT
Server: nginx/1.8.0
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: 420authorization.com
Referer: http://www.google.com/search?q=420authorization.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 420authorization.com
Referer: http://www.google.com/search?q=420authorization.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=420authorization.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://420authorization.com/
Result: 420authorization.com is not infected or malware details are not published yet.
Result: 420authorization.com is not infected or malware details are not published yet.