Scanned pages/files
Request | Server response | Status |
http://www.pt-incn.com/ | HTTP/1.1 200 OK Date: Sat, 09 May 2015 23:32:23 GMT Accept-Ranges: bytes ETag: "8393d2e21f19d01:75a3" Server: Microsoft-IIS/6.0 Content-Length: 3556 Content-Location: http://www.pt-incn.com/index.html Content-Type: text/html Last-Modified: Tue, 16 Dec 2014 11:03:13 GMT | clean |
http://www.pt-incn.com/index.html | 200 OK Content-Length: 3556 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HaCkeD By Ombres <html><head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>HaCkeD By Ombres</title> <meta name="keywords" content="anonymous team x"> <meta name="description" content="HaCkeD By Ombre"> <link rel="icon" href="http://www.img.lc/i/pakistan.png" type="image/x-icon"> <style type="text/css"> <!--body,td,th {color: #CCCCCC;} body {background-color: #000000;} .style1 {font-family: Calibri;font-size: 10pt;} .style2 {color: #FF0000;font-weigh ...[3592 bytes skipped]... | ||
http://www.pt-incn.com/test404page.js | HTTP/1.1 200 OK Date: Sat, 09 May 2015 23:32:26 GMT Accept-Ranges: bytes ETag: "5e7e282cac1cf1:75a3" Server: Microsoft-IIS/6.0 Content-Length: 1419 Content-Location: http://www.pt-incn.com/404.html?404;http://www.pt-incn.com:80/test404page.js Content-Type: text/html Last-Modified: Tue, 26 Aug 2014 08:46:05 GMT | clean |
http://www.pt-incn.com/404.html?404;http://www.pt-incn.com:80/test404page.js | 200 OK Content-Length: 1419 Content-Type: text/html | clean |
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: pt-incn.com
Result:
GET / HTTP/1.1
Host: pt-incn.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: pt-incn.com
Referer: http://www.google.com/search?q=pt-incn.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: pt-incn.com
Referer: http://www.google.com/search?q=pt-incn.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pt-incn.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://pt-incn.com/
Result: pt-incn.com is not infected or malware details are not published yet.
Result: pt-incn.com is not infected or malware details are not published yet.