New scan:

Malware Scanner report for crayola-color-me.com

Malicious/Suspicious/Total urls checked
0/0/20
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/1
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

HaCked by Malaysia Security Tester  (94 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://crayola-color-me.com/
200 OK
Content-Length: 1670
Content-Type: text/html
suspicious
Deface/Content modification. The following signature was found: HaCked by Malaysia Security Tester

<html>
<head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<link rel="icon"
type="image/png" href="http://s.ecrater.com/stores/288395/5159dea3288e5_288395n.jpg" />
<title>HaCked by Malaysia Security Tester</title>
<meta name="description" content="Hacked By Zerk">
<meta name="keywords" content="Zerk">
<meta name="author" content="Malaysian Security Tester">
<body text="white" style="background-color:black;" oncontextmenu='return false;' onkeydown='return false;' onmousedown='return false;'>
<div>
<center><img src="http://i.imgur.com/16As0ax.jpg" width="617
...[1277 bytes skipped]...


http://crayola-color-me.com/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Sat, 07 Jun 2014 08:33:16 GMT
Location: http://www.gogvo.com/404.html
Server: Apache
Content-Length: 213
Content-Type: text/html; charset=iso-8859-1
clean
http://www.gogvo.com/404.html
HTTP/1.1 200 OK
Connection: close
Date: Sat, 07 Jun 2014 08:33:17 GMT
Accept-Ranges: bytes
ETag: "2bd0007-d6-4e9923a08e0c0"
Server: Apache
Content-Length: 214
Content-Type: text/html; charset=UTF-8
Last-Modified: Fri, 25 Oct 2013 15:15:55 GMT
clean
http://www.joeltherien.com/go/pureleverage
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sat, 07 Jun 2014 08:33:17 GMT
Location: http://www.launchv.com/cashapp
Server: Apache
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.2.13
clean
http://www.launchv.com/cashapp
HTTP/1.1 302 Found
Connection: close
Date: Sat, 07 Jun 2014 08:33:17 GMT
Location: http://www.launchv.com/index.php?ref=cashapp
Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 228
Content-Type: text/html; charset=iso-8859-1
clean
http://www.launchv.com/index.php?ref=cashapp
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 07 Jun 2014 08:33:18 GMT
Location: http://launchv.com/?ref=cashapp
Server: Apache/2.4.9 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: ref=cashapp; expires=Mon, 07-Jul-2014 08:33:18 GMT; path=/
X-Pingback: http://launchv.com/xmlrpc.php
X-Powered-By: PHP/5.3.28
clean
http://launchv.com/?ref=cashapp
200 OK
Content-Length: 20554
Content-Type: text/html
clean
http://launchv.com/wp-includes/js/jquery/jquery.js?ver=1.11.0
200 OK
Content-Length: 96402
Content-Type: application/javascript
clean
http://launchv.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 7200
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/jquery/jquery.noconflict.min.js?ver=2.2.0.2
200 OK
Content-Length: 1142
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/jquery/jquery.loadScript.min.js?ver=2.2.0.2
200 OK
Content-Length: 301
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/modules/blog/video/flowplayerHTML5/flowplayer.min.js?ver=2.2.0.2
200 OK
Content-Length: 34245
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/modules/blog/video/mediaelement/mediaelement-and-player.min.js?ver=2.2.0.2
200 OK
Content-Length: 69770
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/modules/blog/video/video-audio-player.min.js?ver=2.2.0.2
200 OK
Content-Length: 3676
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/jquery/jquery.placeholder.min.js?ver=2.2.0.2
200 OK
Content-Length: 1960
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/fancybox/jquery.fancybox.pack.min.js?ver=2.2.0.2
200 OK
Content-Length: 15844
Content-Type: application/javascript
clean
http://launchv.com/wp-includes/js/comment-reply.min.js?ver=3.9.1
200 OK
Content-Length: 757
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/menus.min.js?ver=2.2.0.2
200 OK
Content-Length: 661
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/tooltipster.min.js?ver=2.2.0.2
200 OK
Content-Length: 13816
Content-Type: application/javascript
clean
http://launchv.com/wp-content/themes/optimizePressTheme/lib/js/selectnav.min.js?ver=2.2.0.2
200 OK
Content-Length: 1882
Content-Type: application/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: crayola-color-me.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 07 Jun 2014 08:33:15 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1670
Content-Type: text/html
Last-Modified: Mon, 24 Mar 2014 14:31:28 GMT

...1670 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: crayola-color-me.com
Referer: http://www.google.com/search?q=crayola-color-me.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=crayola-color-me.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://crayola-color-me.com/

Result: crayola-color-me.com is not infected or malware details are not published yet.