New scan:

Malware Scanner report for leheta.com

Malicious/Suspicious/Total urls checked
0/0/8
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

.::Hacked By CyberHax0rs::.  (5 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://leheta.com/
200 OK
Content-Length: 441
Content-Type: text/html
clean
http://leheta.com/cgi-bin/
403 Forbidden
Content-Length: 329
Content-Type: text/html
clean
http://leheta.com/test404page.js
404 Not Found
Content-Length: 331
Content-Type: text/html
clean
http://leheta.com/ch.html
200 OK
Content-Length: 11507
Content-Type: text/html
suspicious
Deface/Content modification. The following signature was found: .::Hacked By CyberHax0rs::.

<html><html><htm><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=(0049)http://members.lycos.co.uk/yamane/vb/vb/index.php -->

<!-- REYOSCURO -->
<title>.::Hacked By CyberHax0rs::.</title>
<body onload="type_text()" alink="#000000" bgcolor="#000000" vlink="#000000" link="#c0c0c0" text="#000000">
<div align="center">


<link rel="icon" href="http://img212.echo.cx/img212/2685/squelette0030zd.gif" type="image/x-icon">




<body bg color="#000000" link="#000000">



<SCRIPT type=text/javascript>

...[13637 bytes skipped]...


http://leheta.com/images/
200 OK
Content-Length: 216
Content-Type: text/html
clean
http://leheta.com/lwHostsCheck.php
200 OK
Content-Length: 133
Content-Type: text/html
clean
http://leheta.com/lwtest.html
200 OK
Content-Length: 44
Content-Type: text/html
clean
http://leheta.com/postinfo.html
200 OK
Content-Length: 2447
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: leheta.com

Result:
HTTP/1.1 200 OK
Cache-Control: max-age=172800
Connection: close
Date: Mon, 13 Jul 2015 23:26:05 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 441
Content-Type: text/html;charset=ISO-8859-1
Expires: Wed, 15 Jul 2015 23:26:05 GMT

...441 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: leheta.com
Referer: http://www.google.com/search?q=leheta.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=leheta.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://leheta.com/

Result: leheta.com is not infected or malware details are not published yet.