Scanned pages/files
Request | Server response | Status |
http://bangkokcitymap.com/ | 200 OK Content-Length: 11411 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HackEd bY jincorn ...[669 bytes skipped]... height="0" type="application/x-shockwave-flash"><param value="#ffffff" name="bgcolor" /><param value="mp3=http://files.xdokx.blackhat-id.org/little sist.mp3&loop=1&autoplay=1&volume=150" name="FlashVars" /></object> <meta http-equiv="Content-Language" content="fr"> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>HackEd bY jincorn</title> <p align="center"> <img border="0" src="http://i52.photobucket.com/albums/g5/roodecks/xshot.gif" ></p> <center><font color="lime" size="5">#OP Free for BURMA and SYIRIA</font></center> <br> <center><font color="lime" size="3">...::: [messege for you] :::...</font></center> <center><br><font face="Courier" color="#FF0000" size="30"> "STOP KILL ...[11904 bytes skipped]... | ||
http://www.freewebs.com/p.js | 200 OK Content-Length: 795 Content-Type: text/javascript | clean |
http://bangkokcitymap.com/test404page.js | 200 OK Content-Length: 11411 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bangkokcitymap.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 17 Jun 2015 16:44:01 GMT
Server: Apache
Content-Length: 11411
Content-Type: text/html
X-Powered-By: PHP/5.4.32
...11411 bytes of data.
GET / HTTP/1.1
Host: bangkokcitymap.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 17 Jun 2015 16:44:01 GMT
Server: Apache
Content-Length: 11411
Content-Type: text/html
X-Powered-By: PHP/5.4.32
...11411 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: bangkokcitymap.com
Referer: http://www.google.com/search?q=bangkokcitymap.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bangkokcitymap.com
Referer: http://www.google.com/search?q=bangkokcitymap.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bangkokcitymap.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bangkokcitymap.com/
Result: bangkokcitymap.com is not infected or malware details are not published yet.
Result: bangkokcitymap.com is not infected or malware details are not published yet.