Scanned pages/files
Request | Server response | Status |
http://crystalballs.co.za/ | 200 OK Content-Length: 584 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by Virus Attacker <title>Crystal balls and Star Signs. Fortune telling by psychics and clairvoyants</title> <body BGCOLOR="black"> <center> <br><br><br><br><br><br><br><br><br> <img src="http://i60.tinypic.com/2qd20d2.gif"> <br> <font face="Impact" color="lime" size="50"> Hacked by Virus Attacker <font face="Georgia" size="3"><br> Pakistan Zindabad <a href="http://www.facebook.com/Cyb3rBoy" target="_blank"><img src="http://www.testyproduc.fr/wordpress/Images/FB.png" alt="facebook" width="95" height="100" style="position:fixed;top:200px;right:10px; border: #000"></a> </body></html> | ||
http://crystalballs.co.za/test404page.js | 404 Not Found Content-Length: 543 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: crystalballs.co.za
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Jul 2014 19:33:23 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
X-Pingback: http://crystalballs.co.za/xmlrpc.php
X-Powered-By: PHP/5.4.30
GET / HTTP/1.1
Host: crystalballs.co.za
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Jul 2014 19:33:23 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
X-Pingback: http://crystalballs.co.za/xmlrpc.php
X-Powered-By: PHP/5.4.30
Second query (visit from search engine):
GET / HTTP/1.1
Host: crystalballs.co.za
Referer: http://www.google.com/search?q=crystalballs.co.za
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: crystalballs.co.za
Referer: http://www.google.com/search?q=crystalballs.co.za
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=crystalballs.co.za
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://crystalballs.co.za/
Result: crystalballs.co.za is not infected or malware details are not published yet.
Result: crystalballs.co.za is not infected or malware details are not published yet.