Scanned pages/files
Request | Server response | Status |
http://globalpmllc.com/ | 200 OK Content-Length: 21330 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By ZiruX ----ZUL VIRUX--- ...[216 bytes skipped]... ument.layers||document.getElementById&&!document.all){ if (e.which==2||e.which==3){ alert(message); return false; } } } if (document.layers){ document.captureEvents(Event.MOUSEDOWN); document.onmousedown=clickNS4; } else if (document.all&&!document.getElementById){ document.onmousedown=clickIE4; } document.oncontextmenu=new Function("alert(message);return false") </script> <title>Hacked By ZiruX ----ZUL VIRUX---</title> <!-- untuk salju --> <object width="1" height="14" data="http://flash-mp3-player.net/medias/player_mp3_mini.swf" type="application/x-shockwave-flash"> <param value="http://flash-mp3-player.net/medias/player_mp3_mini.swf" name="movie"> <param value="#fff" name="bgcolor"> <param value="mp3=http://api.ning.com/files/c9o2k-qynZrIL1ejfFhvRZympB2CifaTjQRl*U-1gB0EDInvZugxLqvUMTVk065XdT7bBDTyPnnCXYZJmBNojWX5 ...[25034 bytes skipped]... | ||
http://globalpmllc.com/test404page.js | 404 Not Found Content-Length: 2674 Content-Type: text/html | clean |
http://cdn.dsultra.com/js/registrar.js | 200 OK Content-Length: 1652 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: globalpmllc.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 24 Jun 2014 02:55:11 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 21330
Content-Type: text/html
Last-Modified: Wed, 15 May 2013 15:42:46 GMT
...21330 bytes of data.
GET / HTTP/1.1
Host: globalpmllc.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 24 Jun 2014 02:55:11 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 21330
Content-Type: text/html
Last-Modified: Wed, 15 May 2013 15:42:46 GMT
...21330 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: globalpmllc.com
Referer: http://www.google.com/search?q=globalpmllc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: globalpmllc.com
Referer: http://www.google.com/search?q=globalpmllc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=globalpmllc.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://globalpmllc.com/
Result: globalpmllc.com is not infected or malware details are not published yet.
Result: globalpmllc.com is not infected or malware details are not published yet.