Scanned pages/files
Request | Server response | Status |
http://sirlancelot.biz/ | 200 OK Content-Length: 6118 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19470 Content-Type: text/javascript | clean |
http://sirlancelot.biz/index.html | 200 OK Content-Length: 6118 Content-Type: text/html | clean |
http://sirlancelot.biz/properties/search.php | 200 OK Content-Length: 8448 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HackeD By mGoD Hacker ...[111 bytes skipped]... />scrollbar-3dlight-color: #FF0000; scrollbar-arrow-color: #F8F8FF; scrollbar-darkshadow-color: #FF0000; scrollbar-face-color: #000000; scrollbar-highlight-color: #FF0000; scrollbar-shadow-color: #FF0000; scrollbar-track-color: #F8F8FF} </STYLE> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>HackeD By mGoD Hacker</title> </head> <body> <html dir="rtl"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>صفحة جديدة 1</title> </head> <body> ...[11143 bytes skipped]... | ||
http://sirlancelot.biz/test404page.js | 404 Not Found Content-Length: 962 Content-Type: text/html | clean |
http://sirlancelot.biz/application.html | 200 OK Content-Length: 2242 Content-Type: text/html | clean |
http://sirlancelot.biz/makepayment.html | 200 OK Content-Length: 4517 Content-Type: text/html | clean |
http://sirlancelot.biz/contact.html | 200 OK Content-Length: 3498 Content-Type: text/html | clean |
http://sirlancelot.biz/SirLancelot_Rentals_Application.pdf | 200 OK Content-Length: 151229 Content-Type: application/pdf | clean |
http://sirlancelot.biz/application/application.php | 200 OK Content-Length: 31712 Content-Type: text/html | clean |
http://sirlancelot.biz//smarticon.geotrust.com/si.js/ | 404 Not Found Content-Length: 962 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sirlancelot.biz
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 09:41:24 GMT
Accept-Ranges: bytes
ETag: "b940370-17e6-4bde1c1c447c0"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4
Content-Length: 6118
Content-Type: text/html
Last-Modified: Tue, 17 Apr 2012 15:40:23 GMT
...6118 bytes of data.
GET / HTTP/1.1
Host: sirlancelot.biz
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 09:41:24 GMT
Accept-Ranges: bytes
ETag: "b940370-17e6-4bde1c1c447c0"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4
Content-Length: 6118
Content-Type: text/html
Last-Modified: Tue, 17 Apr 2012 15:40:23 GMT
...6118 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sirlancelot.biz
Referer: http://www.google.com/search?q=sirlancelot.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sirlancelot.biz
Referer: http://www.google.com/search?q=sirlancelot.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sirlancelot.biz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sirlancelot.biz/
Result: sirlancelot.biz is not infected or malware details are not published yet.
Result: sirlancelot.biz is not infected or malware details are not published yet.