Scanned pages/files
Request | Server response | Status |
http://crafteajunction.com/ | 200 OK Content-Length: 834 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HaCKed by Khan <div style="background-color:black;color:yellow;position:fixed;top:0px;left:0px;width:100%;height:100%;text-align:center;padding-top:99px;font-size:50px;z-index:;line-height:99px;">HaCKed by Khan<br><bar>Saman-Khan-Saman-black-khatar-aMir.Khan-amir-gorgin-Mr.BmR-majidkord84>>Biz varken heckin tadi yok<br><bar>ID:hacker.khan@xtra.co.nz<br><bar>Khan-khatar<!-- mihantools.net --->
<img src="http://s6.uplod.ir/i/00503/wp6ahosl4miw.png "></center> <a href=><object type="application/x-shockwave-flash" width="" height=""data="htt ...[321 bytes skipped]... | ||
http://crafteajunction.com/test404page.js | 404 Not Found Content-Length: 400 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: crafteajunction.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 01 Dec 2015 08:05:44 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 834
Content-Type: text/html
Last-Modified: Tue, 24 Feb 2015 21:52:56 GMT
...834 bytes of data.
GET / HTTP/1.1
Host: crafteajunction.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 01 Dec 2015 08:05:44 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 834
Content-Type: text/html
Last-Modified: Tue, 24 Feb 2015 21:52:56 GMT
...834 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: crafteajunction.com
Referer: http://www.google.com/search?q=crafteajunction.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: crafteajunction.com
Referer: http://www.google.com/search?q=crafteajunction.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=crafteajunction.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://crafteajunction.com/
Result: crafteajunction.com is not infected or malware details are not published yet.
Result: crafteajunction.com is not infected or malware details are not published yet.