Scanned pages/files
Request | Server response | Status |
http://lzkhl.com/ | 200 OK Content-Length: 47646 Content-Type: text/html | clean |
http://lzkhl.com/index.php | 200 OK Content-Length: 47646 Content-Type: text/html | clean |
http://lzkhl.com/list.php?id=1 | 200 OK Content-Length: 9536 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By NeX.L!NUX ...[6424 bytes skipped]... n="left"><table width="100%" border="0" cellspacing="0" cellpadding="0"> <tr> <td> <table width="100%" border="0" cellspacing="0" cellpadding="3"> <tr> <td width="1" align="center"><img src="images/2.gif" /></td> <td><a href="display.php?id=123"> <font color="#000000">Hacked By NeX.L!NUX</font></a></td> </tr> <tr> <td height="3" colspan="2" align="center" background="images/xh_r8_c5.jpg"></td> </tr> <tr> <td width="1" align="center"><img src="images/2.gif" /></td> <td><a href="display.php?id=121"> <font color="#000000">Hacked By NeX.L!NUX</font></a></td> </tr> ...[5080 bytes skipped]... | ||
http://lzkhl.com/info2.php?id=7 | 200 OK Content-Length: 8459 Content-Type: text/html | clean |
http://lzkhl.com/list.php?id=3 | 200 OK Content-Length: 13507 Content-Type: text/html | clean |
http://lzkhl.com/list.php?id=4 | 200 OK Content-Length: 11379 Content-Type: text/html | clean |
http://lzkhl.com/list.php?id=5 | 200 OK Content-Length: 9591 Content-Type: text/html | clean |
http://lzkhl.com/list.php?id=2 | 200 OK Content-Length: 15889 Content-Type: text/html | clean |
http://lzkhl.com/info.php?id=5 | 200 OK Content-Length: 5794 Content-Type: text/html | clean |
http://lzkhl.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://lzkhl.com/display.php?id=124 | 200 OK Content-Length: 7767 Content-Type: text/html | clean |
http://lzkhl.com/display.php?id=119 | 200 OK Content-Length: 7767 Content-Type: text/html | clean |
http://lzkhl.com/display.php?id=118 | 200 OK Content-Length: 6778 Content-Type: text/html | clean |
http://lzkhl.com/display.php?id=115 | 200 OK Content-Length: 7914 Content-Type: text/html | clean |
http://lzkhl.com/display.php?id=111 | 200 OK Content-Length: 17384 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lzkhl.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 16 Feb 2015 04:57:48 GMT
Pragma: no-cache
Server: IIS
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=clgvat8s7obbq9569j6e19d6u7; path=/
X-Powered-By: WAF/2.0
X-Powered-By: WAF/2.0
GET / HTTP/1.1
Host: lzkhl.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 16 Feb 2015 04:57:48 GMT
Pragma: no-cache
Server: IIS
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=clgvat8s7obbq9569j6e19d6u7; path=/
X-Powered-By: WAF/2.0
X-Powered-By: WAF/2.0
Second query (visit from search engine):
GET / HTTP/1.1
Host: lzkhl.com
Referer: http://www.google.com/search?q=lzkhl.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lzkhl.com
Referer: http://www.google.com/search?q=lzkhl.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lzkhl.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://lzkhl.com/
Result: lzkhl.com is not infected or malware details are not published yet.
Result: lzkhl.com is not infected or malware details are not published yet.