Scanned pages/files
Request | Server response | Status |
http://bankbattery.com/ | 200 OK Content-Length: 4711 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HaCkeD By KamraN HellisH ...[121 bytes skipped]... gt; <title>KamraN HellisH</title> <style> body{background:#222 url(http://i.imgur.com/aVdOT.png) repeat; font-family:'Cosmic Sans'} GWMc/cok.gif) scroll repeat center center; </style> </script> <br><br><br><br><br><br><br><br><br><font color=green size=10> HaCkeD By KamraN HellisH<br> kamranhellish@gmail.com<br><font size=5 color=brown> Not Forget KamraN HellisH<br> <font size=5 color=brown>Israel Will Destroy<font size=5 color=brown><br>our Lifes Are For Iran<font size=5 color=red><br>for Understand Your Bugs contact me ;) <body> <object type="application/x-shockwave-flash" width="17" height="17"data="http://www.uploadmusic.org/musicplayer.swf?song_ur ...[4586 bytes skipped]... | ||
http://bankbattery.com/test404page.js | 404 Not Found Content-Length: 485 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bankbattery.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 19 Aug 2014 13:53:31 GMT
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.3.28
GET / HTTP/1.1
Host: bankbattery.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 19 Aug 2014 13:53:31 GMT
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: bankbattery.com
Referer: http://www.google.com/search?q=bankbattery.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bankbattery.com
Referer: http://www.google.com/search?q=bankbattery.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bankbattery.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bankbattery.com/
Result: bankbattery.com is not infected or malware details are not published yet.
Result: bankbattery.com is not infected or malware details are not published yet.