Scanned pages/files
Request | Server response | Status |
http://lifagavs.com.br/ | 200 OK Content-Length: 718 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by Sh0uT0u7 <title>Hacked by Sh0uT0u7</title><link REL="SHORTCUT ICON" HREF="https://cdn1.iconfinder.com/data/icons/finalflags/128/Indonesia-Flag.png">
<center><div id=q><font size=5 face="comic sans ms" color="darkseagreen">Hacked by Sh0uT0u7<br><img src="http://sh0ut0u7.blogs.or.id/images/sj3.png"><br><font size=3>Jje Incovers - ReC0ded - Topi Jerami - ViruzTomcat - ice-cream - Podol - AnakOrang - reg~X - Blitargetar - De4dly_PoiSon - eX-Sh1Ne <br> MrTieDie - Freezer22 - AdrElite - MR.COM - IsanDeCader - Sh0uT0u7 - R3dh34d - Xpronator2 - Syncronizer - Eitaro Attacker<br><br>./Indonesian Defacer <style>body{overflow:hidden;background-color:black}#q{font:40px impact;color:white;position:absolute;left:0;right:0;top:30%} | ||
http://lifagavs.com.br/test404page.js | 404 Not Found Content-Length: 3671 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lifagavs.com.br
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 Oct 2015 15:18:25 GMT
Accept-Ranges: bytes
ETag: "152816c-2ce-5068e6bf69c80"
Server: Apache mod_fcgid/2.3.5
Content-Length: 718
Content-Type: text/html
Last-Modified: Wed, 29 Oct 2014 11:54:10 GMT
...718 bytes of data.
GET / HTTP/1.1
Host: lifagavs.com.br
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 Oct 2015 15:18:25 GMT
Accept-Ranges: bytes
ETag: "152816c-2ce-5068e6bf69c80"
Server: Apache mod_fcgid/2.3.5
Content-Length: 718
Content-Type: text/html
Last-Modified: Wed, 29 Oct 2014 11:54:10 GMT
...718 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: lifagavs.com.br
Referer: http://www.google.com/search?q=lifagavs.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lifagavs.com.br
Referer: http://www.google.com/search?q=lifagavs.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lifagavs.com.br
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://lifagavs.com.br/
Result: lifagavs.com.br is not infected or malware details are not published yet.
Result: lifagavs.com.br is not infected or malware details are not published yet.