Scanned pages/files
Request | Server response | Status |
http://newshademarketing.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 17 Jul 2015 01:50:06 GMT Location: http://www.newshademarketing.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.newshademarketing.com/xmlrpc.php X-Powered-By: PHP/5.5.9-1ubuntu4.11 | clean |
http://www.newshademarketing.com/ | 200 OK Content-Length: 40170 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By KaracaBey ...[4445 bytes skipped]... agespeed.cf.0lQJbmGL5B.css' type='text/css' media='all'/> <link rel='stylesheet' id='rs-settings-css' href='http://www.newshademarketing.com/wp-content/plugins/revslider/rs-plugin/css/settings.css' type='text/css' media='all'/> <style id='rs-captions-css' media='all'><body style='color: transparent;background-color: black'><center><h1><b style='color: white'><center>Hacked By KaracaBey<br>KaracaBey - Memo<p style='color: transparent'></style> <link rel='stylesheet' id='g1_screen-css' href='http://www.newshademarketing.com/wp-content/themes/3clicks/css/g1-screen.css' type='text/css' media='screen'/> <link rel='stylesheet' id='g1_dynamic_style-css' href='http://www.newshademarketing.com/wp-content/themes/3clicks/css/A.g1-dynamic-style.php,qrespondjs=no.pagespeed.cf.O47iRC1Hjp.css' type='text/css' media='screen'/> ...[41056 bytes skipped]... | ||
http://www.newshademarketing.com/wp-includes/js/jquery/jquery.js | 200 OK Content-Length: 95952 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-includes/js/jquery/jquery-migrate.min.js | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js | 200 OK Content-Length: 83792 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/modernizr/modernizr.custom.js | 200 OK Content-Length: 5386 Content-Type: application/javascript | clean |
https://www.google.com/recaptcha/api.js | 200 OK Content-Length: 532 Content-Type: text/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/respond/respond.src.js | 200 OK Content-Length: 9628 Content-Type: application/javascript | clean |
http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit2 | 200 OK Content-Length: 1450 Content-Type: text/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/main.js | 200 OK Content-Length: 94857 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/jquery.touchSwipe/jquery.touchSwipe.min.js | 200 OK Content-Length: 8262 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/galleria/galleria-1.2.9.min.js | 200 OK Content-Length: 61638 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/galleria/themes/classic/galleria.classic.js | 200 OK Content-Length: 2712 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/lib/g1-simple-sliders/js/g1-simple-sliders.js | 200 OK Content-Length: 44151 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-includes/js/comment-reply.min.js | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://www.newshademarketing.com/wp-content/themes/3clicks/js/jquery-metadata/jquery.metadata.js | 200 OK Content-Length: 5112 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: newshademarketing.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 17 Jul 2015 01:50:06 GMT
Location: http://www.newshademarketing.com/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.newshademarketing.com/xmlrpc.php
X-Powered-By: PHP/5.5.9-1ubuntu4.11
...0 bytes of data.
GET / HTTP/1.1
Host: newshademarketing.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 17 Jul 2015 01:50:06 GMT
Location: http://www.newshademarketing.com/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.newshademarketing.com/xmlrpc.php
X-Powered-By: PHP/5.5.9-1ubuntu4.11
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: newshademarketing.com
Referer: http://www.google.com/search?q=newshademarketing.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: newshademarketing.com
Referer: http://www.google.com/search?q=newshademarketing.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=newshademarketing.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://newshademarketing.com/
Result: newshademarketing.com is not infected or malware details are not published yet.
Result: newshademarketing.com is not infected or malware details are not published yet.