Scanned pages/files
Request | Server response | Status |
http://jahan1414.ir/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 27 May 2015 05:46:56 GMT Location: http://jahan1414.ir/cms/ Server: Apache Content-Length: 232 Content-Type: text/html; charset=iso-8859-1 | clean |
http://jahan1414.ir/cms/ | 200 OK Content-Length: 3846 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 0x0 src: http://www.youtube.com/embed/lshcweod81s?autoplay=1&replay=1 <iframe width="0" height="0" src="http://www.youtube.com/embed/lshcweod81s?autoplay=1&replay=1" frameborder="0" allowfullscreen=""> Deface/Content modification. The following signature was found: Hacked By Hani Xavi <head> <meta http-equiv="Content-Language" content="fr"> <title>Hacked By Hani Xavi</title> </head> <body bgcolor="#000000"> <p class="style5" align="center" style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-s ...[4350 bytes skipped]... | ||
http://jahan1414.ir/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: jahan1414.ir
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 27 May 2015 05:46:56 GMT
Location: http://jahan1414.ir/cms/
Server: Apache
Content-Length: 232
Content-Type: text/html; charset=iso-8859-1
...232 bytes of data.
GET / HTTP/1.1
Host: jahan1414.ir
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 27 May 2015 05:46:56 GMT
Location: http://jahan1414.ir/cms/
Server: Apache
Content-Length: 232
Content-Type: text/html; charset=iso-8859-1
...232 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: jahan1414.ir
Referer: http://www.google.com/search?q=jahan1414.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: jahan1414.ir
Referer: http://www.google.com/search?q=jahan1414.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=jahan1414.ir
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://jahan1414.ir/
Result: jahan1414.ir is not infected or malware details are not published yet.
Result: jahan1414.ir is not infected or malware details are not published yet.