Scanned pages/files
Request | Server response | Status |
http://moruchina.com/ | 200 OK Content-Length: 438 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: hacked by b3z <title>hacked by b3z</title><body bgcolor="black"><img src="http://wapkaimage.com/400713/400713829_e695b73235.jpg" /><font color="white"><p>brain LIVES----B3Z IS AROUND</p></font></body>
<iframe src='http://brainshome.com'>hahah</iframe> <!-- --> <script type='text/javascript' src='//go.pub2srv.com/apu.php?zoneid=16780'> </script> <script type="text/javascript" src="//1phads.com/notice.php?p=16781&interactive=1&pushup=1"> </script> | ||
http://moruchina.com//go.pub2srv.com/apu.php?zoneid=16780/ | HTTP/1.1 302 Found Connection: close Date: Sat, 11 Jul 2015 20:44:12 GMT Location: http://redirect.main-hosting.com/error404.php/20?domain=moruchina.com Server: Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
http://redirect.main-hosting.com/error404.php/20?domain=moruchina.com | 200 OK Content-Length: 148 Content-Type: text/html | clean |
http://redirect.main-hosting.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sat, 11 Jul 2015 20:44:13 GMT Location: http://error.hostinger.eu? Server: Apache Content-Length: 210 Content-Type: text/html; charset=iso-8859-1 | clean |
http://error.hostinger.eu?/ | HTTP/1.1 200 OK Connection: close Date: Sat, 11 Jul 2015 20:44:13 GMT Server: nginx/1.7.11 Content-Type: text/html; charset=UTF-8 | clean |
http://www.hostinger.lt/klaida_404? | 200 OK Content-Length: 11736 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js | 200 OK Content-Length: 91556 Content-Type: text/javascript | clean |
http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.14/jquery-ui.min.js | 200 OK Content-Length: 201658 Content-Type: text/javascript | clean |
http://redirect.main-hosting.com/js/site.php | HTTP/1.1 302 Found Connection: close Date: Sat, 11 Jul 2015 20:44:15 GMT Location: http://error.hostinger.eu? Server: Apache Content-Length: 210 Content-Type: text/html; charset=iso-8859-1 | clean |
http://error.hostinger.eu?/test404page.js | HTTP/1.1 200 OK Connection: close Date: Sat, 11 Jul 2015 20:44:15 GMT Server: nginx/1.7.11 Content-Type: text/html; charset=UTF-8 | clean |
http://www.hostinger.lt/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://redirect.main-hosting.com/js/popup.js | HTTP/1.1 302 Found Connection: close Date: Sat, 11 Jul 2015 20:44:16 GMT Location: http://error.hostinger.eu? Server: Apache Content-Length: 210 Content-Type: text/html; charset=iso-8859-1 | clean |
http://moruchina.com//1phads.com/notice.php?p=16781&interactive=1&pushup=1/ | HTTP/1.1 302 Found Connection: close Date: Sat, 11 Jul 2015 20:44:17 GMT Location: http://redirect.main-hosting.com/error404.php/20?domain=moruchina.com Server: Content-Length: 253 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: moruchina.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 11 Jul 2015 20:44:11 GMT
Server:
Content-Length: 438
Content-Type: text/html
X-Powered-By: PHP/5.3.24
...438 bytes of data.
GET / HTTP/1.1
Host: moruchina.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 11 Jul 2015 20:44:11 GMT
Server:
Content-Length: 438
Content-Type: text/html
X-Powered-By: PHP/5.3.24
...438 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: moruchina.com
Referer: http://www.google.com/search?q=moruchina.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: moruchina.com
Referer: http://www.google.com/search?q=moruchina.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=moruchina.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://moruchina.com/
Result: moruchina.com is not infected or malware details are not published yet.
Result: moruchina.com is not infected or malware details are not published yet.