Scanned pages/files
Request | Server response | Status |
http://www.one.com.lb/ | HTTP/1.1 200 OK Date: Sun, 22 Mar 2015 20:38:11 GMT Accept-Ranges: bytes ETag: "ac432a7de751d01:261" Server: Microsoft-IIS/6.0 Content-Length: 8373 Content-Location: http://www.one.com.lb/index.html Content-Type: text/html Last-Modified: Thu, 26 Feb 2015 17:13:07 GMT X-Powered-By: ASP.NET | clean |
http://www.one.com.lb/index.html | 200 OK Content-Length: 8373 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by Sub ...[179 bytes skipped]... /www.w3.org/1999/xhtml"> <head> <a href="https://www.facebook.com/Fallaga.Tn"target="_blank"><img src='http://s15.postimg.org/a3x51rzi3/fallaga_logo.png'alt="facebook" width="220" height="170" style='position:fixed;top:50px;right:10px; border: #000'/></a> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="keywords" content="Hacked by Sub'Tn" /> <link rel="icon" href="http://img.freeflagicons.com/thumb/fluttering_flag/tunisia/tunisia_640.png"> <title>Hacked by Fallaga team</title> </head> <body style="background-image:url('http://www.cnjtc.com/wp-content/uploads/2014/02/plain_black_wallpaper_1920x1080_background_wallpapers_-_download_free_1920x1080.jpg')"; oncontextmenu="return false" onkeydown="return false"> <style type="text/css"> ...[9517 bytes skipped]... | ||
http://www.one.com.lb/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: one.com.lb
Result:
GET / HTTP/1.1
Host: one.com.lb
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: one.com.lb
Referer: http://www.google.com/search?q=one.com.lb
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: one.com.lb
Referer: http://www.google.com/search?q=one.com.lb
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=one.com.lb
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://one.com.lb/
Result: one.com.lb is not infected or malware details are not published yet.
Result: one.com.lb is not infected or malware details are not published yet.