Scanned pages/files
Request | Server response | Status |
http://poppedphiladelphia.com/ | 200 OK Content-Length: 2165 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Joker Inside <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"> <title>Hacked By Joker Inside</title> <body> <embed src="http://youtube.googleapis.com/v/Hag2JWC8qZ0&autoplay=1" type="application/x-shockwave-flash" wmode="transparent" width="1" height="1"></embed> <body oncontextmenu='return false;' onkeydown='return false;' onmousedown='return false;'> <body background="http://splashmagazine.com/wp-content/uploads/2013/02/Black-Background-Metal-black-wallpaper.jpg ...[2052 bytes skipped]... | ||
http://hbhost.googlecode.com/files/snow.js | 404 Not Found Content-Length: 944 Content-Type: text/html | clean |
http://hbhost.googlecode.com//www.google.com/ | 404 Not Found Content-Length: 931 Content-Type: text/html | clean |
http://hbhost.googlecode.com/test404page.js | 404 Not Found Content-Length: 945 Content-Type: text/html | clean |
http://poppedphiladelphia.com//www.google.com/ | 200 OK Content-Length: 2165 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: poppedphiladelphia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 19 Nov 2013 22:23:48 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: poppedphiladelphia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 19 Nov 2013 22:23:48 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: poppedphiladelphia.com
Referer: http://www.google.com/search?q=poppedphiladelphia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: poppedphiladelphia.com
Referer: http://www.google.com/search?q=poppedphiladelphia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=poppedphiladelphia.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://poppedphiladelphia.com/
Result: poppedphiladelphia.com is not infected or malware details are not published yet.
Result: poppedphiladelphia.com is not infected or malware details are not published yet.