Scanned pages/files
Request | Server response | Status |
http://dunwoodyhair.com/ | 200 OK Content-Length: 2122 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by WarLock ...[809 bytes skipped]... <title>./njothISD</title> <embed src="http://www129.indowebster.com/p187viutah6ve1i7t1hhe1h1k1p5a3.swf" type="application/x-shockwave-flash" wmode="show" width="1" height="1"></embed> <a href=""><img src="https://fbcdn-sphotos-c-a.akamaihd.net/hphotos-ak-ash3/t1/526590_1396131997297225_1955430079_n.jpg" /></a> <center><title>Hacked by WarLock</title><link rel="SHORTCUT ICON" href="http://upload.wikimedia.org/wikipedia/en/5/54/Unlock-icon.gif"><div align="center"> <br> <center><font face="Ravie"><font size="5" color=white><blink><font color=cyan>./njothISD feat</font> ./ISD_Highlander</blink></font><br></center> <br> <body oncontextmenu='return false;' onkeydown='return false;' onmous ...[810 bytes skipped]... | ||
http://dunwoodyhair.com/BidVertiser.dbm?pid=296727&bid=726696 | 404 Not Found Content-Length: 465 Content-Type: text/html | clean |
http://dunwoodyhair.com/test404page.js | 404 Not Found Content-Length: 464 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: dunwoodyhair.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 02 Sep 2014 18:29:21 GMT
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Type: text/html
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: dunwoodyhair.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 02 Sep 2014 18:29:21 GMT
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Type: text/html
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: dunwoodyhair.com
Referer: http://www.google.com/search?q=dunwoodyhair.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: dunwoodyhair.com
Referer: http://www.google.com/search?q=dunwoodyhair.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=dunwoodyhair.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://dunwoodyhair.com/
Result: dunwoodyhair.com is not infected or malware details are not published yet.
Result: dunwoodyhair.com is not infected or malware details are not published yet.