Scanned pages/files
Request | Server response | Status |
http://clasicgroup.com/ | 200 OK Content-Length: 6135 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Cyber_Ps ...[3298 bytes skipped]... t;<a href="select-lang.php">عربÙ</a></li> </ul> </div> <!--End Hmenu--> </div> <!--End Header--><!--Main--> <div id="main"> <!--Main-h--> <div id="main-h"> <!--Home--> <!--Home--> <div id="home"> <h1>Clasic Group</h1><br /> <p> Hacked By Cyber_Ps you Have Bean Hacked ...</p><br clear="all" /> <a href="page.php?id=1">Read more</a> </div> <!--End Home--><!--End Home--> </div> <!--End Main-h--> <!--Content--> <div id="content"> <!--Side--> <!--Side--> <div id="side"> <!--Side title--> <div id="side ...[4456 bytes skipped]... | ||
http://clasicgroup.com/js/jquery-1.3.2.min.js | 200 OK Content-Length: 57272 Content-Type: application/javascript | clean |
http://clasicgroup.com/index.php | 200 OK Content-Length: 6135 Content-Type: text/html | clean |
http://clasicgroup.com/page.php?id=1 | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 04 Apr 2015 00:46:19 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding,User-Agent Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=1ff38f9bccdf2c16c3fd654536aa505c; path=/ X-Powered-By: PHP/5.3.29 | clean |
http://www.google.com/ | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sat, 04 Apr 2015 00:46:18 GMT Location: http://www.google.lt/?gws_rd=cr&ei=WjQfVYb7N4KSsAGYrIOgCQ Server: gws Content-Length: 258 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.5 P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info." Set-Cookie: PREF=ID=871adc1560f243f0:FF=0:TM=1428108378:LM=1428108378:S=3jM2ecRpPtR5Q6Uk; expires=Mon, 03-Apr-2017 00:46:18 GMT; path=/; domain=.google.com Set-Cookie: NID=67=L-RYzk_Y57RucHr_BCxAnrgJ1la-aQWcFcAOrvq3myRqXAqRfNy1FtHi2_bpVF7DlbkGOhf44-epuJ93EEFypfo9WoaYwD1FPRd5Y2t7j8uL-jWAGfvp6UAQfrRSaWUY; expires=Sun, 04-Oct-2015 00:46:18 GMT; path=/; domain=.google.com; HttpOnly X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/?gws_rd=cr&ei=wjqfvyb7n4kssagyriogcq | 200 OK Content-Length: 51579 Content-Type: text/html | clean |
https://www.google.lt/webhp?tab=ww | 200 OK Content-Length: 64360 Content-Type: text/html | clean |
https://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 57922 Content-Type: text/html | clean |
https://www.google.lt/webhp?hl=lt&tab=iw | 200 OK Content-Length: 64367 Content-Type: text/html | clean |
http://www.google.lt/intl/lt/options/ | HTTP/1.1 301 Moved Permanently Cache-Control: public, max-age=2592000 Connection: close Date: Mon, 30 Mar 2015 12:14:45 GMT Age: 390695 Location: http://www.google.lt/intl/lt/about/products/ Server: sffe Content-Length: 241 Content-Type: text/html; charset=UTF-8 Expires: Wed, 29 Apr 2015 12:14:45 GMT Alternate-Protocol: 80:quic,p=0.5 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block | clean |
http://www.google.lt/intl/lt/about/products/ | 200 OK Content-Length: 7068 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/js/gweb/analytics/autotrack.js/ | 404 Not Found Content-Length: 1471 Content-Type: text/html | clean |
http://www.google.lt//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.google.lt/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://www.google.lt/preferences?hl=lt | 200 OK Content-Length: 65796 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=wi | 200 OK Content-Length: 51583 Content-Type: text/html | clean |
http://www.google.lt/imghp?hl=lt&tab=ii | 200 OK Content-Length: 51551 Content-Type: text/html | clean |
http://www.google.lt/history/optout?hl=lt | HTTP/1.1 302 Found Cache-Control: private Connection: close Date: Sat, 04 Apr 2015 00:46:21 GMT Location: https://history.google.com/history/optout?hl=lt Server: Search-History HTTP Server Content-Length: 244 Content-Type: text/html; charset=UTF-8 Alternate-Protocol: 80:quic,p=0.5 Set-Cookie: PREF=ID=4f4bce335a7da6f8:TM=1428108381:LM=1428108381:S=RoQqUOfHRSeuixOX; expires=Mon, 03-Apr-2017 00:46:21 GMT; path=/; domain=.google.lt X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
https://history.google.com/history/optout?hl=lt | 200 OK Content-Length: 36866 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: clasicgroup.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Apr 2015 00:46:17 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=411870f369c789f530db88206bdd0668; path=/
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: clasicgroup.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Apr 2015 00:46:17 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=411870f369c789f530db88206bdd0668; path=/
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: clasicgroup.com
Referer: http://www.google.com/search?q=clasicgroup.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: clasicgroup.com
Referer: http://www.google.com/search?q=clasicgroup.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=clasicgroup.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://clasicgroup.com/
Result: clasicgroup.com is not infected or malware details are not published yet.
Result: clasicgroup.com is not infected or malware details are not published yet.