Scanned pages/files
Request | Server response | Status |
http://www.joelrookwood.com/ | 200 OK Content-Length: 36425 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By ...[441 bytes skipped]... tle> <!-- Stylesheets --> <link rel="stylesheet" href="<html> </head><body alink="gray" bgcolor="black" vlink="gray" link="gray" text="white" charset="utf-8"><center> <title>ICSG</title> <center> <br> <script src="http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js"></script>HACKED By Iran-Cyber , Owned By Iran-Cyber , Defaced By iran-cyber , hack by iran-cyber , Hacked By Iran Cyber Security group <br><br> <font size=2 Color=red>Hacked By Iran Cyber Security group<br><br>/wp-content/themes/scope/style.css" type="text/css" media="screen" /> <!-- RSS & Pingbacks --> <link rel="alternate" type="application/rss+xml" title="JoelRookwood.com RSS Feed" href="http://www.joelrookwood.com/feed/" /> <link rel="pingback" href="<html> ...[40156 bytes skipped]... | ||
http://s1.upload7.ir/downloads/7OqszdxCChgeP22kZWEGsoNSHeaqFbnD/ic.js | 200 OK Content-Length: 1138 Content-Type: application/x-javascript | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...211 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/test404page.js | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...222 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...243 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...243 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...238 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...212 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...259 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...237 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...228 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...230 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...228 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
http://html_/headbody_alink=%22gray%22+bgcolor%3D%22black%22+vlink%3D%22gray%22+link%3D%22gray%22+text%3D%22white%22+charset%3D%22utf-8%22%3E%3Ccenter%3E+%3Ctitle%3EICSG%3C%2Ftitle%3E+%3Ccenter%3E+%3Cbr%3E+%3Cscript+src%3D%22http%3A%2F%2Fs1.upload7.ir%2Fdownloads%2F7OqszdxCChgeP22kZWEGsoNSHeaqFbnD%2Fic.js%22%3E%3C%2Fscript%3EHACKED+By+Iran-Cyber+%2C+Owned+By+Iran-Cyber+%2C+Defaced+By+iran-cyber+%2 <span>...233 symbols skipped</span> | 500 Can't connect to html_:80 Content-Length: 180 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: joelrookwood.com
Result:
GET / HTTP/1.1
Host: joelrookwood.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: joelrookwood.com
Referer: http://www.google.com/search?q=joelrookwood.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: joelrookwood.com
Referer: http://www.google.com/search?q=joelrookwood.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=joelrookwood.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://joelrookwood.com/
Result: joelrookwood.com is not infected or malware details are not published yet.
Result: joelrookwood.com is not infected or malware details are not published yet.