Scanned pages/files
Request | Server response | Status |
http://www.holidayinsrilanka.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 21 Jul 2015 09:11:08 GMT Location: http://holidayinsrilanka.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://holidayinsrilanka.com/xmlrpc.php X-Powered-By: PHP/5.4.34 | clean |
http://holidayinsrilanka.com/ | 200 OK Content-Length: 1360 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by Turkhackteam.Org <title>Hacked by Turkhackteam.Org</title>
<body bgcolor="Black" /> <body oncontextmenu="return false" onselectstart="return false" ondragstart="return false"></body> <img align="left" src="http://i564.photobucket.com/albums/ss87/Mafya_67/zix0zc.png" /> <img align="right" src="http://i564.photobucket.com/albums/ss87/Mafya_67/66da48.png" /> <center><img src="http://www.turkhackteam.org/images ...[1180 bytes skipped]... | ||
http://holidayinsrilanka.com/test404page.js | 404 Not Found Content-Length: 9587 Content-Type: text/html | clean |
http://holidayinsrilanka.com/wp-includes/js/jquery/jquery.js?ver=1.11.2 | 200 OK Content-Length: 95952 Content-Type: application/javascript | clean |
http://holidayinsrilanka.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://holidayinsrilanka.com/wp-content/themes/twentyfourteen/js/functions.js?ver=20140616 | 200 OK Content-Length: 3449 Content-Type: application/javascript | clean |
http://holidayinsrilanka.com/hacked-by-sanalordu-net-tyqex-ynr-tgrl5000/ | 200 OK Content-Length: 12475 Content-Type: text/html | clean |
http://holidayinsrilanka.com/wp-includes/js/comment-reply.min.js?ver=4.2.2 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://holidayinsrilanka.com/sample-page/ | 200 OK Content-Length: 14700 Content-Type: text/html | clean |
http://holidayinsrilanka.com/wordpress/wp-admin/ | 404 Not Found Content-Length: 9587 Content-Type: text/html | clean |
http://holidayinsrilanka.com/2014/09/23/hello-world/ | 200 OK Content-Length: 30799 Content-Type: text/html | clean |
http://holidayinsrilanka.com/author/admin/ | 200 OK Content-Length: 12307 Content-Type: text/html | clean |
http://holidayinsrilanka.com/2014/09/ | 200 OK Content-Length: 12135 Content-Type: text/html | clean |
http://holidayinsrilanka.com/category/uncategorized/ | 200 OK Content-Length: 12363 Content-Type: text/html | clean |
http://holidayinsrilanka.com/wp-login.php | 200 OK Content-Length: 2701 Content-Type: text/html | clean |
http://holidayinsrilanka.com/wp-login.php?action=lostpassword | 200 OK Content-Length: 2344 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: holidayinsrilanka.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 21 Jul 2015 09:11:10 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
X-Pingback: http://holidayinsrilanka.com/xmlrpc.php
X-Powered-By: PHP/5.4.34
GET / HTTP/1.1
Host: holidayinsrilanka.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 21 Jul 2015 09:11:10 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
X-Pingback: http://holidayinsrilanka.com/xmlrpc.php
X-Powered-By: PHP/5.4.34
Second query (visit from search engine):
GET / HTTP/1.1
Host: holidayinsrilanka.com
Referer: http://www.google.com/search?q=holidayinsrilanka.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: holidayinsrilanka.com
Referer: http://www.google.com/search?q=holidayinsrilanka.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=holidayinsrilanka.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://holidayinsrilanka.com/
Result: holidayinsrilanka.com is not infected or malware details are not published yet.
Result: holidayinsrilanka.com is not infected or malware details are not published yet.