Scanned pages/files
Request | Server response | Status |
http://sprimonteoliennes.be/ | 200 OK Content-Length: 409 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By ~ Yunus Incredibl <!--base64_decode ('WTI5dWRHRmpkQ0J0WlNBOVBpQm9kSFJ3T2k4dlptRmpaV0p2YjJzdVkyOXRMM2wxYm5WelpHWm5aR1puTVRJek1UVTE=')--><title>Hacked By ~ Yunus Incredibl</title><style>body{background-color: black}h1{color:white; text-shadow:0 0 20px #ffFFFF; font-size:50px;font-weight:bold;font-family: courier new}</style><center><br><br><br><br><br><br><br><br><br><br>
<h1>Hacked By ~ Yunus Incredibl</h1><br><br></center> | ||
http://sprimonteoliennes.be/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sprimonteoliennes.be
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 12 Apr 2014 09:59:08 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: mailplanBAK=R2555565549; path=/; expires=Sat, 12-Apr-2014 11:17:00 GMT
Set-Cookie: mailplan=R3858288693; path=/; expires=Sat, 12-Apr-2014 11:15:44 GMT
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: sprimonteoliennes.be
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 12 Apr 2014 09:59:08 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: mailplanBAK=R2555565549; path=/; expires=Sat, 12-Apr-2014 11:17:00 GMT
Set-Cookie: mailplan=R3858288693; path=/; expires=Sat, 12-Apr-2014 11:15:44 GMT
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: sprimonteoliennes.be
Referer: http://www.google.com/search?q=sprimonteoliennes.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sprimonteoliennes.be
Referer: http://www.google.com/search?q=sprimonteoliennes.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sprimonteoliennes.be
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sprimonteoliennes.be/
Result: sprimonteoliennes.be is not infected or malware details are not published yet.
Result: sprimonteoliennes.be is not infected or malware details are not published yet.