Scanned pages/files
Request | Server response | Status |
http://primeispat.com/ | 200 OK Content-Length: 6815 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By: Anon Hawk ...[437 bytes skipped]... 0 0 10px #004eff, 0 0 20px #004eff, 0 0 45px #004eff, 0 0 40px #004eff; }</style> <style> .link{ color: #FFF; font-size:22px; } .link:hover{ font-size:30px; color: #360; } </style> <link rel="SHORTCUT ICON" href="http://s.myniceprofile.com/myspacepic/1/th/152.gif"> </head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="description" content="Hacked By: Anon Hawk"> <meta name="keywords" content="Hacked By:Anon Hawk"> <meta name="author" content="Hacked By: Anon Hawk"> <title>Hacked By Anon Hawk </title> </head> <body style=" cursor: url(http://i60.tinypic.com/qrndzr.gif) ; background-image:url(http://i59.tinypic.com/i3z0h3.gif) ; background-attachment:fixed;"> <div id="fb-root"></div> <script>(function(d, s, id) { var js, fjs = d.getElementsByTagName(s)[0]; if (d.getEl ...[6766 bytes skipped]... | ||
http://primeispat.com/test404page.js | 404 Not Found Content-Length: 406 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: primeispat.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 29 Mar 2015 04:51:13 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
GET / HTTP/1.1
Host: primeispat.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 29 Mar 2015 04:51:13 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: primeispat.com
Referer: http://www.google.com/search?q=primeispat.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: primeispat.com
Referer: http://www.google.com/search?q=primeispat.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=primeispat.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://primeispat.com/
Result: primeispat.com is not infected or malware details are not published yet.
Result: primeispat.com is not infected or malware details are not published yet.