Scanned pages/files
Request | Server response | Status |
http://hacormim.com/ | 200 OK Content-Length: 6714 Content-Type: text/html | clean |
http://hacormim.com/index.php?file=kop5.php | 200 OK Content-Length: 21756 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Website Hacked By AnonGhost Team \!/ ~~Death To All Jews~~ | ~~Viva Hamas,Qassam~~ | Website Hacked By AnonGhost Team \!/ ~~Death To All Jews~~ | ~~Viva Hamas,Qassam~~ | <html class="mouse"> <head> <title>HacKeD By AnonGhost</title> <meta http-equiv="Content-Type" content="text/html;charset=UTF-8"> <link href="http://4.bp.blogspot.com/-ozfPCDmEWuQ/U1EIlem1O2I/AAAAAAAAAQA/alm0imwX3MY/s1600/logo.png" rel="icon" type="image/png"> <link type="text/css" rel="stylesheet" href="http://fonts. ...[24224 bytes skipped]... | ||
http://hacormim.com//connect.facebook.net/en_GB/all.js/ | 404 Not Found Content-Length: 618 Content-Type: text/html | clean |
http://hacormim.com/test404page.js | 404 Not Found Content-Length: 618 Content-Type: text/html | clean |
http://platform.twitter.com/widgets.js | 200 OK Content-Length: 115360 Content-Type: application/javascript | clean |
http://yondarkness.googlecode.com/files/AntiCopas.js | 403 Forbidden Content-Length: 2155 Content-Type: text/html | clean |
http://yondarkness.googlecode.com//www.google.com/ | 404 Not Found Content-Length: 1425 Content-Type: text/html | clean |
http://hacormim.com/googledrive.com/host/0B0FAryoVedK0Szk4WW9GR3ZKWDg/modernizr.custom.86080.js | 404 Not Found Content-Length: 618 Content-Type: text/html | clean |
http://wagerfield.github.io/parallax/assets/scripts/js/libraries.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 02 Mar 2015 16:38:21 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://matthew.wagerfield.com/parallax/assets/scripts/js/libraries.min.js Server: GitHub.com Vary: Accept-Encoding Content-Length: 178 Content-Type: text/html X-Cache: MISS X-Cache-Hits: 0 X-Served-By: cache-fra1238-FRA X-Timer: S1425314301.631199,VS0,VE88 | clean |
http://matthew.wagerfield.com/parallax/assets/scripts/js/libraries.min.js | 200 OK Content-Length: 128590 Content-Type: application/javascript | clean |
http://wagerfield.github.io/parallax/deploy/jquery.parallax.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 02 Mar 2015 16:38:22 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://matthew.wagerfield.com/parallax/deploy/jquery.parallax.js Server: GitHub.com Vary: Accept-Encoding Content-Length: 178 Content-Type: text/html X-Cache: MISS X-Cache-Hits: 0 X-Served-By: cache-fra1248-FRA X-Timer: S1425314302.450144,VS0,VE88 | clean |
http://matthew.wagerfield.com/parallax/deploy/jquery.parallax.js | 200 OK Content-Length: 17641 Content-Type: application/javascript | clean |
http://hacormim.com/index.php?file=kop4.php | 200 OK Content-Length: 21756 Content-Type: text/html | clean |
http://hacormim.com/index.php?file=kop3.php | 200 OK Content-Length: 21756 Content-Type: text/html | clean |
http://hacormim.com/index.php?file=kop1.php | 200 OK Content-Length: 21756 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hacormim.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 02 Mar 2015 16:38:18 GMT
Accept-Ranges: bytes
Content-Length: 6714
Content-Type: text/html
Last-Modified: Wed, 16 Sep 2009 13:33:15 GMT
...6714 bytes of data.
GET / HTTP/1.1
Host: hacormim.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 02 Mar 2015 16:38:18 GMT
Accept-Ranges: bytes
Content-Length: 6714
Content-Type: text/html
Last-Modified: Wed, 16 Sep 2009 13:33:15 GMT
...6714 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: hacormim.com
Referer: http://www.google.com/search?q=hacormim.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hacormim.com
Referer: http://www.google.com/search?q=hacormim.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hacormim.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hacormim.com/
Result: hacormim.com is not infected or malware details are not published yet.
Result: hacormim.com is not infected or malware details are not published yet.