Scanned pages/files
Request | Server response | Status |
http://www.casin-it.com/ | HTTP/1.1 200 OK Date: Sun, 24 May 2015 04:15:55 GMT Accept-Ranges: bytes ETag: "186e3a8bfa46d01:77e1" Server: Microsoft-IIS/6.0 Content-Length: 2363 Content-Location: http://www.casin-it.com/index.html Content-Type: text/html Last-Modified: Thu, 12 Feb 2015 19:31:48 GMT | clean |
http://www.casin-it.com/index.html | 200 OK Content-Length: 2363 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED BY darkshadow-tn <html><head> <title>HACKED BY darkshadow-tn</title> </head> <body bgcolor="black"> <center><font size="14px" color="Red" <h1=""><b>#Hacked by Ombre</b></font></center> <br><br> <center><font size="12px" color="green" <h2=""><b></b></font></center><b><br></b> <center><font size="6px" color="green">&l ...[2560 bytes skipped]... | ||
http://www.casin-it.com/test404page.js | HTTP/1.1 200 OK Date: Sun, 24 May 2015 04:16:00 GMT Accept-Ranges: bytes ETag: "544d65e6a3afcf1:77e1" Server: Microsoft-IIS/6.0 Content-Length: 1370 Content-Location: http://www.casin-it.com/404.html?404;http://www.casin-it.com:80/test404page.js Content-Type: text/html Last-Modified: Mon, 04 Aug 2014 05:21:09 GMT | clean |
http://www.casin-it.com/404.html?404;http://www.casin-it.com:80/test404page.js | 200 OK Content-Length: 1370 Content-Type: text/html | clean |
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: casin-it.com
Result:
GET / HTTP/1.1
Host: casin-it.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: casin-it.com
Referer: http://www.google.com/search?q=casin-it.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: casin-it.com
Referer: http://www.google.com/search?q=casin-it.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=casin-it.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://casin-it.com/
Result: casin-it.com is not infected or malware details are not published yet.
Result: casin-it.com is not infected or malware details are not published yet.