Scanned pages/files
Request | Server response | Status |
http://apostlepierrebennett.com/ | 200 OK Content-Length: 6135 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: == Hacked By v1ru5-Gr0up Cyber Army == ...[180 bytes skipped]... at.dyna.ultraweb.hu/pgstat.js?server=3&username=ggrttar" type="text/javascript"></script><script language="Javascript"> <!-- HTML Encryption provided by iWEBTOOL.com --> <!-- //--> </script> <link rel="SHORTCUT ICON" href="http://i39.tinypic.com/1z6yuq0.jpg"> <script type="text/javascript"> //<![CDATA[ msg = "== Hacked By v1ru5-Gr0up Cyber Army =="; msg = "" + msg;pos = 0; function scrollMSG() { document.title = msg.substring(pos, msg.length) + msg.substring(0, pos); pos++; if (pos > msg.length) pos = 0 window.setTimeout("scrollMSG()",80); } scrollMSG(); //]]></script><title>==========-Hacked By v1ru5-Gr0up Cyber Army-===========-[+]v1ru5-Gr0up Cyber army </title> <style type="text/css"> body{ background:url(http:/ ...[6885 bytes skipped]... | ||
http://stat.dyna.ultraweb.hu/pgstat.js?server=2&username=ggrttar | 200 OK Content-Length: 130 Content-Type: text/html | clean |
http://stat.dyna.ultraweb.hu/test404page.js | 404 Not Found Content-Length: 345 Content-Type: text/html | clean |
http://stat.dyna.ultraweb.hu/pgstat.js?server=3&username=ggrttar | 200 OK Content-Length: 130 Content-Type: text/html | clean |
http://goo.gl/2ejf7 | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Fri, 11 Apr 2014 10:01:06 GMT Pragma: no-cache Location: http://edhoo-xp.googlecode.com/files/hadling.js Server: GSE Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT Alternate-Protocol: 80:quic X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://edhoo-xp.googlecode.com/files/hadling.js | 200 OK Content-Length: 2662 Content-Type: text/plain | clean |
http://yondarkness.googlecode.com/files/AntiCopas.js | 200 OK Content-Length: 2016 Content-Type: text/plain | clean |
http://yondarkness.googlecode.com/files/ | 404 Not Found Content-Length: 1431 Content-Type: text/html | clean |
http://yondarkness.googlecode.com//www.google.com/ | 404 Not Found Content-Length: 1425 Content-Type: text/html | clean |
http://x.dickeymaru.com/y | 500 Can't connect to x.dickeymaru.com:80 (Bad hostname) Content-Length: 164 Content-Type: text/plain | clean |
http://www.sis-kj.com/js/3.js | 404 Not Found Content-Length: 476 Content-Type: text/html | clean |
http://4.bp.blogspot.com/-2h8LgjUDpzY/T0fTA4EQx8I/AAAAAAAAAtU/n_W5Vby8zLU/s400/hacked.gif | 200 OK Content-Length: 39251 Content-Type: image/gif | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: apostlepierrebennett.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 11 Apr 2014 10:01:04 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
X-Pingback: http://apostlepierrebennett.com/xmlrpc.php
GET / HTTP/1.1
Host: apostlepierrebennett.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 11 Apr 2014 10:01:04 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
X-Pingback: http://apostlepierrebennett.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: apostlepierrebennett.com
Referer: http://www.google.com/search?q=apostlepierrebennett.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: apostlepierrebennett.com
Referer: http://www.google.com/search?q=apostlepierrebennett.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=apostlepierrebennett.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://apostlepierrebennett.com/
Result: apostlepierrebennett.com is not infected or malware details are not published yet.
Result: apostlepierrebennett.com is not infected or malware details are not published yet.