Scanned pages/files
Request | Server response | Status |
http://exboyfriend-guru.com/ | 200 OK Content-Length: 63625 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: +ADw-/title+AD4APA-title+AD4-Hacked By Imam+ADw-/title+AD4 <!DOCTYPE HTML>
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"> <head> <meta charset="UTF-7" /> <title>How To Get Your Ex Boyfriend Back Easily</title><link rel="profile" href="http://gmpg.org/xfn/11" /> <link rel="alternate" type="application/rss+xml" title="+ADw-/title+AD4APA-title+AD4-Hacked By Imam+ADw-/title+AD4 TeamCyberAssassins+ADw-DIV style+AD0AIg-DISPLAY: none+ACIAPgA8-xmp+AD4- RSS Feed" href="http://exboyfriend-guru.com/feed/" /> <link rel="pingback" href="http://exboyfriend-guru.com/xmlrpc.php" /> <link rel="stylesheet" href="http://exboyfriend-guru.com/wp-content/themes/arjuna-x/style.css" type="text/css" media="screen" /> <!--[if lte IE 7]><link rel="stylesheet" hre ...[71344 bytes skipped]... | ||
http://exboyfriend-guru.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://exboyfriend-guru.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://exboyfriend-guru.com/wp-content/themes/arjuna-x/default.js?ver=3.7.11 | 200 OK Content-Length: 9375 Content-Type: application/javascript | clean |
http://exboyfriend-guru.com/wp-content/plugins/counterize/counterize.js.php?ver=3.7.11 | 200 OK Content-Length: 11282 Content-Type: text/javascript | clean |
http://exboyfriend-guru.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.46.0-2013.11.21 | 200 OK Content-Length: 14798 Content-Type: application/javascript | clean |
http://exboyfriend-guru.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.6 | 200 OK Content-Length: 7691 Content-Type: application/javascript | clean |
http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201551 | 200 OK Content-Length: 10372 Content-Type: application/x-javascript | clean |
http://s.gravatar.com/js/gprofiles.js?ver=2015Decaa | 200 OK Content-Length: 20650 Content-Type: application/x-javascript | clean |
http://exboyfriend-guru.com/wp-content/plugins/jetpack/modules/wpgroho.js?ver=3.7.11 | 200 OK Content-Length: 930 Content-Type: application/javascript | clean |
http://stats.wordpress.com/e-201551.js | 200 OK Content-Length: 3334 Content-Type: application/x-javascript | clean |
http://exboyfriend-guru.com/contact-us/ | 200 OK Content-Length: 28838 Content-Type: text/html | clean |
http://exboyfriend-guru.com/wp-includes/js/comment-reply.min.js?ver=3.7.11 | 200 OK Content-Length: 753 Content-Type: application/javascript | clean |
http://exboyfriend-guru.com/how-to-get-him-back-fast-review/ | 200 OK Content-Length: 33277 Content-Type: text/html | clean |
http://exboyfriend-guru.com/feed/ | 200 OK Content-Length: 68465 Content-Type: text/xml | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: exboyfriend-guru.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 18 Dec 2015 17:07:31 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://wp.me/2tSVl>; rel=shortlink
Ngpass_ngall: 1
Set-Cookie: PHPSESSID=7bd47308f534196caae0368d31d6e03a; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
X-Pingback: http://exboyfriend-guru.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: exboyfriend-guru.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 18 Dec 2015 17:07:31 GMT
Pragma: no-cache
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://wp.me/2tSVl>; rel=shortlink
Ngpass_ngall: 1
Set-Cookie: PHPSESSID=7bd47308f534196caae0368d31d6e03a; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
Set-Cookie: adinj=1; expires=Fri, 18-Dec-2015 18:07:31 GMT; path=/
X-Pingback: http://exboyfriend-guru.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: exboyfriend-guru.com
Referer: http://www.google.com/search?q=exboyfriend-guru.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: exboyfriend-guru.com
Referer: http://www.google.com/search?q=exboyfriend-guru.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=exboyfriend-guru.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://exboyfriend-guru.com/
Result: exboyfriend-guru.com is not infected or malware details are not published yet.
Result: exboyfriend-guru.com is not infected or malware details are not published yet.