Scanned pages/files
Request | Server response | Status |
http://sakhimedia.com/ | 200 OK Content-Length: 803 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Jhoker ...[139 bytes skipped]... t;img Size="large"src="http://1.bp.blogspot.com/-UdAKRNFNT_k/U2S_Ps5ErDI/AAAAAAAAKBQ/-NCjzEH4hPA/s1600/Who+am+I+Riddle+For+Children.jpg" height="250"></center> <br><center><font face="Courier New"><font size="4"><font color="black">====================================================================================<br> <br><center><font color="red"><b>Hacked By Jhoker <br>Indonesian Security Tester</b></font></center> <br><center><font color="white"><b>SAKHI MEDIA GOT HACKED ? look : http://www.zone-h.org/archive/notifier=jhoker</b></font></center> <br><center><font face="Courier New"><font size="4"><font color="black">====================================================================================<br> | ||
http://sakhimedia.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sakhimedia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 29 Oct 2014 19:40:32 GMT
Accept-Ranges: bytes
ETag: "374a19f-323-5035cc239dd80"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_qos/10.10
Content-Length: 803
Content-Type: text/html
Last-Modified: Thu, 18 Sep 2014 20:23:34 GMT
...803 bytes of data.
GET / HTTP/1.1
Host: sakhimedia.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 29 Oct 2014 19:40:32 GMT
Accept-Ranges: bytes
ETag: "374a19f-323-5035cc239dd80"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_qos/10.10
Content-Length: 803
Content-Type: text/html
Last-Modified: Thu, 18 Sep 2014 20:23:34 GMT
...803 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sakhimedia.com
Referer: http://www.google.com/search?q=sakhimedia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sakhimedia.com
Referer: http://www.google.com/search?q=sakhimedia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sakhimedia.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sakhimedia.com/
Result: sakhimedia.com is not infected or malware details are not published yet.
Result: sakhimedia.com is not infected or malware details are not published yet.