Scanned pages/files
Request | Server response | Status |
http://balipratamavillas.com/ | 200 OK Content-Length: 11711 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: +ADw-/title+AD4APA-title+AD4-Hacked By Imam+ADw-/title+AD4 <!DOCTYPE html> <html lang="en-US"> <head> <meta charset="UTF-7" /> <title>+ADw-/title+AD4APA-title+AD4-Hacked By Imam+ADw-/title+AD4 TeamCyberAssassins+ADw-DIV style+AD0AIg-DISPLAY: none+ACIAPgA8-xmp+AD4- | Pratama Villas | Bali Villas Resort</title> <link rel="profile" href="http://gmpg.org/xfn/11" /> <link rel="stylesheet" type="text/css" media="all" href="http://balipratamavillas.com/wp-content/themes/bumilinggah/style.css" /> <link rel="pingback" href="http://balipratamavillas.com/xmlrpc.ph ...[13718 bytes skipped]... | ||
http://balipratamavillas.com/wp-content/plugins/easing-slider/js/jquery.js?ver=1.4.2 | 200 OK Content-Length: 67836 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/plugins/easing-slider/js/jquery.easing.js?ver=1.3 | 200 OK Content-Length: 8097 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/plugins/easing-slider/js/script.js?ver=1.2 | 200 OK Content-Length: 11344 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/themes/bumilinggah/js/jquery.jcarousel.min.js | 200 OK Content-Length: 9916 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/themes/bumilinggah/js/tinydropdown.js | 200 OK Content-Length: 2087 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/plugins/contact-form-7/jquery.form.js?ver=3.08 | 200 OK Content-Length: 37156 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/plugins/contact-form-7/scripts.js?ver=3.1.2 | 200 OK Content-Length: 6208 Content-Type: application/javascript | clean |
http://balipratamavillas.com/villa-type/ | 200 OK Content-Length: 18002 Content-Type: text/html | clean |
http://balipratamavillas.com/wp-includes/js/comment-reply.min.js?ver=3.5.1 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://balipratamavillas.com/wp-content/plugins/nextgen-gallery-optimizer/fancybox/jquery.fancybox-1.3.4.pack.js?ver=1.3.4 | 200 OK Content-Length: 15602 Content-Type: application/javascript | clean |
http://balipratamavillas.com/1-bedroom/ | 200 OK Content-Length: 34192 Content-Type: text/html | clean |
http://balipratamavillas.com/2-bedroom/ | 200 OK Content-Length: 12278 Content-Type: text/html | clean |
http://balipratamavillas.com/3-bedroom/ | 200 OK Content-Length: 16467 Content-Type: text/html | clean |
http://balipratamavillas.com/bumi-linggah/ | 200 OK Content-Length: 11228 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: balipratamavillas.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 25 Dec 2015 21:01:33 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=bfdfa90fe9b55bce26193f946c4823ff; path=/
X-Pingback: http://balipratamavillas.com/xmlrpc.php
X-Powered-By: PHP/5.4.45
GET / HTTP/1.1
Host: balipratamavillas.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 25 Dec 2015 21:01:33 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=bfdfa90fe9b55bce26193f946c4823ff; path=/
X-Pingback: http://balipratamavillas.com/xmlrpc.php
X-Powered-By: PHP/5.4.45
Second query (visit from search engine):
GET / HTTP/1.1
Host: balipratamavillas.com
Referer: http://www.google.com/search?q=balipratamavillas.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: balipratamavillas.com
Referer: http://www.google.com/search?q=balipratamavillas.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=balipratamavillas.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://balipratamavillas.com/
Result: balipratamavillas.com is not infected or malware details are not published yet.
Result: balipratamavillas.com is not infected or malware details are not published yet.