Scanned pages/files
Request | Server response | Status |
http://kvkthoubal.org/ | 200 OK Content-Length: 44111 Content-Type: text/html | clean |
http://kvkthoubal.org/site/wp-content/themes/kvkthoubal_ver-1.0/js/jquery-1.2.6.min.js | 200 OK Content-Length: 55774 Content-Type: application/javascript | clean |
http://kvkthoubal.org/site/wp-includes/js/l10n.js?ver=20101110 | 200 OK Content-Length: 308 Content-Type: application/javascript | clean |
http://kvkthoubal.org/site/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.2 | 200 OK Content-Length: 9808 Content-Type: application/javascript | clean |
http://kvkthoubal.org/site/wp-includes/js/jquery/jquery.js?ver=1.4.4 | 200 OK Content-Length: 78620 Content-Type: application/javascript | clean |
http://kvkthoubal.org/site/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.88 | 200 OK Content-Length: 31032 Content-Type: application/javascript | clean |
http://kvkthoubal.org/site/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.05 | 200 OK Content-Length: 1750 Content-Type: application/javascript | clean |
http://kvkthoubal.org/ | 200 OK Content-Length: 44111 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: +ADw-title+AD4-Hacked By Ayy+AP0-ld+AP0-z Tim Intenational Force +AHw Sessizce N+APY-bette ...[411 bytes skipped]... +ADw-meta name+AD0AIg-apple-mobile-web-app-capable+ACI content+AD0AIg-yes+ACIAPg +ADw-meta name+AD0AIg-viewport+ACI content+AD0AIg-width+AD0-device-width, initial-scale+AD0-1, maximum-scale+AD0-1, user-scalable+AD0-no+ACIAPg +ADw-meta charset+AD0AIg-utf-8+ACIAPg +ADwAIQ— PAGE TITLE –+AD4 +ADw-title+AD4-Hacked By Ayy+AP0-ld+AP0-z Tim Intenational Force +AHw Sessizce N+APY-betteyiz+ACEAPA-/title+AD4 +ADwAIQ— GOOGLE FONTS –+AD4 +ADw-link href+AD0′http://fonts.googleapis.com/css?family+AD0-Lato:300,400,700+AHw-Raleway:300,400,500+AHw-Open+ACs-Sans:300,400,600,700,800′ rel+AD0′stylesheet’ type+AD0′text/css’+AD4 +ADwAIQ— STYLESHEETS –+A ...[46912 bytes skipped]... | ||
http://kvkthoubal.org/site/ | 200 OK Content-Length: 44129 Content-Type: text/html | clean |
http://kvkthoubal.org/site/ | 200 OK Content-Length: 44129 Content-Type: text/html | clean |
http://kvkthoubal.org/site/about-us/ | 200 OK Content-Length: 60154 Content-Type: text/html | clean |
http://kvkthoubal.org/site/about-us/ | 200 OK Content-Length: 60154 Content-Type: text/html | clean |
http://kvkthoubal.org/site/district-profile/ | 200 OK Content-Length: 59406 Content-Type: text/html | clean |
http://kvkthoubal.org/site/district-profile/ | 200 OK Content-Length: 59406 Content-Type: text/html | clean |
http://kvkthoubal.org/site/faculty/ | 200 OK Content-Length: 60651 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kvkthoubal.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Sep 2015 00:23:22 GMT
Server: nginx
Content-Type: text/html; charset=UTF-7
X-Pingback: http://kvkthoubal.org/site/xmlrpc.php
GET / HTTP/1.1
Host: kvkthoubal.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Sep 2015 00:23:22 GMT
Server: nginx
Content-Type: text/html; charset=UTF-7
X-Pingback: http://kvkthoubal.org/site/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: kvkthoubal.org
Referer: http://www.google.com/search?q=kvkthoubal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kvkthoubal.org
Referer: http://www.google.com/search?q=kvkthoubal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kvkthoubal.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://kvkthoubal.org/
Result: kvkthoubal.org is not infected or malware details are not published yet.
Result: kvkthoubal.org is not infected or malware details are not published yet.