Scanned pages/files
Request | Server response | Status |
http://aferm.nu/ | 200 OK Content-Length: 2369 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Hunter Rim ...[261 bytes skipped]... p-equiv=content-type content=text/html;charset=windows-1254> <META http-equiv=content-type content=text/html;charset=x-mac-turkish> </head> <script type="text/javascript"> </script> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <meta name="keywords" content="B-C"> <meta name="description" content="Hacked By Hunter Rim"><script type="text/javascript"> </script> <script type="text/javascript"> </script> </head> <title>Hunter Rim Was Here</title> <style type="text/css"> --></style> </head> <body> <div align="center"> <script language="JavaScript1.2"> </script> <html> <title></title> </head> <bo ...[1927 bytes skipped]... | ||
http://aferm.nu/test404page.js | 404 Not Found Content-Length: 1835 Content-Type: text/html | clean |
http://citynetwork.se/infopages/global.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 May 2015 01:36:55 GMT Location: https://www.citynetwork.se/infopages/global.js Server: nginx/1.1.19 Content-Length: 185 Content-Type: text/html | clean |
https://www.citynetwork.se/infopages/global.js | 200 OK Content-Length: 151 Content-Type: application/x-javascript | clean |
http://citynetwork.se/infopages/cufon-yui.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 May 2015 01:36:56 GMT Location: https://www.citynetwork.se/infopages/cufon-yui.js Server: nginx/1.1.19 Content-Length: 185 Content-Type: text/html | clean |
https://www.citynetwork.se/infopages/cufon-yui.js | 200 OK Content-Length: 14208 Content-Type: application/x-javascript | clean |
http://citynetwork.se/infopages/AvantGarde.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 May 2015 01:36:56 GMT Location: https://www.citynetwork.se/infopages/AvantGarde.js Server: nginx/1.1.19 Content-Length: 185 Content-Type: text/html | clean |
https://www.citynetwork.se/infopages/avantgarde.js | 404 Not Found Content-Length: 21790 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js?ver=3.4.2 | 200 OK Content-Length: 95786 Content-Type: text/javascript | clean |
https://www.citynetwork.se/wp-includes/js/jquery/jquery.js?ver=1.11.2 | 200 OK Content-Length: 95952 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
https://www.citynetworkhosting.com/wp-content/plugins/social-factory-slider/scripts/jquery.easing.1.2.js?ver=4.2.2 | 200 OK Content-Length: 6898 Content-Type: application/x-javascript | clean |
https://code.jquery.com/ui/1.10.3/jquery-ui.js?ver=4.2.2 | 200 OK Content-Length: 302681 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-content/themes/citynetwork-v4/scripts/foundation/foundation.js?ver=4.2.2 | 200 OK Content-Length: 9891 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-content/themes/citynetwork-v4/scripts/foundation/foundation.forms.js?ver=4.2.2 | 200 OK Content-Length: 13362 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-content/themes/citynetwork-v4/scripts/foundation/foundation.placeholder.js?ver=4.2.2 | 200 OK Content-Length: 4564 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-content/themes/citynetwork-v4/scripts/jquery.autosize.js?ver=4.2.2 | 200 OK Content-Length: 5449 Content-Type: application/x-javascript | clean |
https://www.citynetwork.se/wp-content/themes/citynetwork-v4/scripts/jquery.fancybox.js?ver=4.2.2 | 200 OK Content-Length: 47760 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aferm.nu
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 May 2015 01:36:55 GMT
Via: 1.1 varnish
Age: 0
ETag: "fa1f1a0-941-4f5121166aa40"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Thu, 20 Mar 2014 23:24:17 GMT
X-Cache-Hit: HIT
X-Varnish: 1654512178 1654512177
GET / HTTP/1.1
Host: aferm.nu
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 May 2015 01:36:55 GMT
Via: 1.1 varnish
Age: 0
ETag: "fa1f1a0-941-4f5121166aa40"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Thu, 20 Mar 2014 23:24:17 GMT
X-Cache-Hit: HIT
X-Varnish: 1654512178 1654512177
Second query (visit from search engine):
GET / HTTP/1.1
Host: aferm.nu
Referer: http://www.google.com/search?q=aferm.nu
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aferm.nu
Referer: http://www.google.com/search?q=aferm.nu
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aferm.nu
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://aferm.nu/
Result: aferm.nu is not infected or malware details are not published yet.
Result: aferm.nu is not infected or malware details are not published yet.