Scanned pages/files
Request | Server response | Status |
http://progress-personal.pl/ | 200 OK Content-Length: 5110 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Brwa-Yk ...[1944 bytes skipped]... t;/p><p align="left"><strong><br /></strong></p><p align="left"> </p> </div> <div class="clear"> </div> <div id="aktualno¶ci"> <div class="headboxLeft"> Aktualno¶ci </div> <div id="news"> <p class="title"><a href="info.php?id=3" class="tlink">Hacked By Brwa-Yk</a></p> <p class="content"> <div><!--?php</div--><div>Hacked By Brwa-Yk<span style="white-space: pre" class="Apple-tab-span"> </span></div></div> </p> <p> <img src="http://progress-personal.pl/gfx/1/pl/gfx/progress_sep.png" alt="progress" align="center" HSPACE="5" VSPACE="5" /> </p> </div> </div> ...[3793 bytes skipped]... | ||
http://progress-personal.pl/./js/overlib_mini.js | 200 OK Content-Length: 37153 Content-Type: application/javascript | clean |
http://progress-personal.pl/./js/admin_script.js | 200 OK Content-Length: 6966 Content-Type: application/javascript | clean |
http://progress-personal.pl/./js/browser.js | 200 OK Content-Length: 3302 Content-Type: application/javascript | clean |
http://progress-personal.pl/info.php?id=3 | 200 OK Content-Length: 3708 Content-Type: text/html | clean |
http://progress-personal.pl/index.php | 200 OK Content-Length: 5110 Content-Type: text/html | clean |
http://progress-personal.pl/strona.php?id=4 | 200 OK Content-Length: 17077 Content-Type: text/html | clean |
http://progress-personal.pl/strona.php?id=12 | 200 OK Content-Length: 34728 Content-Type: text/html | clean |
http://progress-personal.pl/strona.php?id=13 | 200 OK Content-Length: 36079 Content-Type: text/html | clean |
http://progress-personal.pl/oferty.php | 200 OK Content-Length: 4948 Content-Type: text/html | clean |
http://progress-personal.pl/strona.php?id=5 | 200 OK Content-Length: 4365 Content-Type: text/html | clean |
http://progress-personal.pl/oferta.php?id=11 | 200 OK Content-Length: 10788 Content-Type: text/html | clean |
http://progress-personal.pl/test404page.js | 404 Not Found Content-Length: 185 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: progress-personal.pl
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 01 Apr 2015 17:08:13 GMT
Pragma: no-cache
Server: IdeaWebServer/v0.80
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b2637d35d5fcec7019ac52e1f6309557; path=/
X-Powered-By: PHP/4.4.9
GET / HTTP/1.1
Host: progress-personal.pl
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 01 Apr 2015 17:08:13 GMT
Pragma: no-cache
Server: IdeaWebServer/v0.80
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b2637d35d5fcec7019ac52e1f6309557; path=/
X-Powered-By: PHP/4.4.9
Second query (visit from search engine):
GET / HTTP/1.1
Host: progress-personal.pl
Referer: http://www.google.com/search?q=progress-personal.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: progress-personal.pl
Referer: http://www.google.com/search?q=progress-personal.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=progress-personal.pl
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://progress-personal.pl/
Result: progress-personal.pl is not infected or malware details are not published yet.
Result: progress-personal.pl is not infected or malware details are not published yet.