Scanned pages/files
Request | Server response | Status |
http://www.bufa120.com/ | HTTP/1.1 200 OK Date: Wed, 13 May 2015 22:33:37 GMT Accept-Ranges: bytes ETag: "35b205f8a47d01:7615" Server: Microsoft-IIS/6.0 Content-Length: 3731 Content-Location: http://www.bufa120.com/index.html Content-Type: text/html Last-Modified: Fri, 13 Feb 2015 12:41:21 GMT | clean |
http://www.bufa120.com/index.html | 200 OK Content-Length: 3731 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By maxkillertn&ombre <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html><head> <meta content="text/html; charset=ISO-8859-1" http-equiv="content-type"><title>Hacked By maxkillertn&ombre</title> </head><body> <div style="text-align: center;"><big style="font-weight: bold; font-style: italic;"><font st ...[3752 bytes skipped]... | ||
http://www.bufa120.com/test404page.js | HTTP/1.1 200 OK Date: Wed, 13 May 2015 22:33:38 GMT Accept-Ranges: bytes ETag: "c4163dac1cf1:7615" Server: Microsoft-IIS/6.0 Content-Length: 1395 Content-Location: http://www.bufa120.com/404.html?404;http://www.bufa120.com:80/test404page.js Content-Type: text/html Last-Modified: Tue, 26 Aug 2014 08:46:33 GMT | clean |
http://www.bufa120.com/404.html?404;http://www.bufa120.com:80/test404page.js | 200 OK Content-Length: 1395 Content-Type: text/html | clean |
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bufa120.com
Result:
GET / HTTP/1.1
Host: bufa120.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: bufa120.com
Referer: http://www.google.com/search?q=bufa120.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bufa120.com
Referer: http://www.google.com/search?q=bufa120.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bufa120.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bufa120.com/
Result: bufa120.com is not infected or malware details are not published yet.
Result: bufa120.com is not infected or malware details are not published yet.