Scanned pages/files
Request | Server response | Status |
http://farmasicilia.com/ | 200 OK Content-Length: 1133 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by viruslegend <html><head></style><embed src="http://www.youtube.com/v/hZsaPu-kthY&hl=en_US&loop=1&feature=related&autoplay=1" type="application/x-shockwave-flash" wmode="transparent" width="1" height="1"></embed>
<title>Hacked by viruslegend</title></head><body background="http://www.madtomatoe.com/wp-content/uploads/2010/11/matrix-animated-image.gif"></body><center><h1 style=color:red;>HaCkeD By VIRUSLEGEND</h1><h2 style=color:green;> VIRUSLEGEND@OUTLOOK.COM </h4><img src="http://3.bp.blogspot.com/-WYL_xsCOb8o/TsSKzTGbnuI/AAAAAAAAASE/VoyntSKwf70/s1600/Hacker.png"><h3 style=color:grey; >VIRUSLEGEND ...[602 bytes skipped]... | ||
http://farmasicilia.com/test404page.js | 404 Not Found Content-Length: 399 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: farmasicilia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 13 Jun 2014 10:14:46 GMT
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.4.17
GET / HTTP/1.1
Host: farmasicilia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 13 Jun 2014 10:14:46 GMT
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.4.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: farmasicilia.com
Referer: http://www.google.com/search?q=farmasicilia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: farmasicilia.com
Referer: http://www.google.com/search?q=farmasicilia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=farmasicilia.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://farmasicilia.com/
Result: farmasicilia.com is not infected or malware details are not published yet.
Result: farmasicilia.com is not infected or malware details are not published yet.