Scanned pages/files
Request | Server response | Status |
http://www.keenlook.com/ | 200 OK Content-Length: 2616 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: [+] Hacked By ...[1353 bytes skipped]... ></style> <iframe width="0" height="0" src="https://www.youtube.com/embed/ASj81daun5Q?autoplay=1" frameborder="0"></iframe> <img class='img' src='https://fbcdn-sphotos-h-a.akamaihd.net/hphotos-ak-xpf1/v/t35.0-12/11229498_1601444870111796_260710965_o.jpg?oh=e4874886559cbbf6b522082bae85d2c7&oe=55543A10&__gda__=1431568192_6f953b9a741da5715381a83630d5a9c7'></img> <h2>[+] Hacked By <a href='https://www.facebook.com/gasmask.system?ref=hl'>GAS_MASK_SYSTEMS</a>[+]</h2> <h4>We Are : <a href='https://www.facebook.com/aiden.pearce.7946'>Backdoor Shell </a><a href='https://www.facebook.com/oussama.boaster'> Kilwa_DZ </a> <a href='https://www.facebook.com/doudou.bourenane.1'> DZ_Blacko</a> <a href='https://www.facebook.com/ismail.kali30'> ViRuS_I1110</a></h4> <p>[+] Di ...[846 bytes skipped]... | ||
http://www.keenlook.com/test404page.js | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://suspended.hostgator.com/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: keenlook.com
Result:
GET / HTTP/1.1
Host: keenlook.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: keenlook.com
Referer: http://www.google.com/search?q=keenlook.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: keenlook.com
Referer: http://www.google.com/search?q=keenlook.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=keenlook.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://keenlook.com/
Result: keenlook.com is not infected or malware details are not published yet.
Result: keenlook.com is not infected or malware details are not published yet.