Scanned pages/files
Request | Server response | Status |
http://edunews.edu.eg/ | 200 OK Content-Length: 44350 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: !--Hacked by -- <!--Hacked by -->
<!DOCTYPE html> <html prefix="og: http://ogp.me/ns#" dir="rtl" lang="ar-aa"> <head> <base href="http://edunews.edu.eg/" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="keywords" content="ÙÙØªÙ اÙÙ ÙÙØ¹ باخبار Ø¨Ø§ÙØªØ¹ÙÙÙ Ù٠٠صر ÙØ§ÙÙØ·Ù Ø§ÙØ¹Ø±Ø¨Ù Ø¨Ù ÙØ§ÙعاÙÙ ÙÙÙ Ø¨ÙØ¯Ù ...[52049 bytes skipped]... | ||
http://edunews.edu.eg/templates/sj_financial/js/jquery.lazyload.js | 200 OK Content-Length: 8166 Content-Type: text/javascript | clean |
http://edunews.edu.eg/test404page.js | 404 Not Found Content-Length: 292 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: edunews.edu.eg
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Dec 2015 17:00:54 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 27 Dec 2015 17:00:55 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: cfd7c917ba7f40c6b2b28d1b4bc33eba=clgup3tuu7fait67abe3gtpcf1; path=/; HttpOnly
Set-Cookie: sj_financial_tpl=sj_financial; expires=Fri, 16-Dec-2016 17:00:54 GMT; path=/
X-Logged-In: False
X-Powered-By: PHP/5.4.31
GET / HTTP/1.1
Host: edunews.edu.eg
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 27 Dec 2015 17:00:54 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 27 Dec 2015 17:00:55 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: cfd7c917ba7f40c6b2b28d1b4bc33eba=clgup3tuu7fait67abe3gtpcf1; path=/; HttpOnly
Set-Cookie: sj_financial_tpl=sj_financial; expires=Fri, 16-Dec-2016 17:00:54 GMT; path=/
X-Logged-In: False
X-Powered-By: PHP/5.4.31
Second query (visit from search engine):
GET / HTTP/1.1
Host: edunews.edu.eg
Referer: http://www.google.com/search?q=edunews.edu.eg
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: edunews.edu.eg
Referer: http://www.google.com/search?q=edunews.edu.eg
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=edunews.edu.eg
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://edunews.edu.eg/
Result: edunews.edu.eg is not infected or malware details are not published yet.
Result: edunews.edu.eg is not infected or malware details are not published yet.