Scanned pages/files
Request | Server response | Status |
http://jremdecor.com/ | 200 OK Content-Length: 10416 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED By HERO MAN <html dir="rtl"> <head> <meta http-equiv="Content-Language" content="en-us"> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>HACKED By HERO MAN </title> <link rel="SHORTCUT ICON" href="http://www.rt.gov.sa/drivingtestpic/045aff0b475c1c1b167a393ffd005b11.gif"> <meta name="keywords" content="HACKED By HERO MAN"> <meta name="Author" content="Febri Alexander Alvino"> <meta name="description" content="HACKED By HERO MAN"/> <meta content='Ferka' name='author'/> <meta name="owner" content="Ferk4"> < ...[12184 bytes skipped]... | ||
http://K4C3-Undetected.googlecode.com/files/Erza Jullian.js | 404 Not Found Content-Length: 1448 Content-Type: text/html | clean |
http://K4C3-Undetected.googlecode.com//www.google.com/ | 404 Not Found Content-Length: 1510 Content-Type: text/html | clean |
http://K4C3-Undetected.googlecode.com/test404page.js | 404 Not Found Content-Length: 1524 Content-Type: text/html | clean |
http://jremdecor.com//www.google.com/ | 404 Not Found Content-Length: 767 Content-Type: text/html | clean |
http://jremdecor.com//ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js/ | 404 Not Found Content-Length: 767 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: jremdecor.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600
Connection: close
Date: Wed, 09 Sep 2015 04:29:20 GMT
Accept-Ranges: bytes
Age: 930
ETag: "28b0-51b912b3b571b"
Server: Apache/2
Content-Length: 10416
Content-Type: text/html
Expires: Wed, 09 Sep 2015 05:13:51 GMT
Last-Modified: Thu, 23 Jul 2015 20:59:53 GMT
...10416 bytes of data.
GET / HTTP/1.1
Host: jremdecor.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600
Connection: close
Date: Wed, 09 Sep 2015 04:29:20 GMT
Accept-Ranges: bytes
Age: 930
ETag: "28b0-51b912b3b571b"
Server: Apache/2
Content-Length: 10416
Content-Type: text/html
Expires: Wed, 09 Sep 2015 05:13:51 GMT
Last-Modified: Thu, 23 Jul 2015 20:59:53 GMT
...10416 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: jremdecor.com
Referer: http://www.google.com/search?q=jremdecor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: jremdecor.com
Referer: http://www.google.com/search?q=jremdecor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=jremdecor.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://jremdecor.com/
Result: jremdecor.com is not infected or malware details are not published yet.
Result: jremdecor.com is not infected or malware details are not published yet.