Scanned pages/files
Request | Server response | Status |
http://summithealthcc.com/ | 200 OK Content-Length: 19784 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED BY MR.WWW ...[12803 bytes skipped]... ;!--- END Slideshow ----------------------------------------------------------> <div class="clearpad"> <div class="blog-featured"> <div class="items-leading"> <div class="leading-0"> <h2 class="item-page-title"> <a href="/index.php/9-uncategorised/24-joomla"> HACKED BY MR.WWW</a> </h2> <p>HACKED BY MR.WWW</p> <div class="item-separator"></div> </div> </div> </div> <!--[if ...[10355 bytes skipped]... | ||
http://summithealthcc.com/media/system/js/core.js | 200 OK Content-Length: 4225 Content-Type: application/x-javascript | clean |
http://summithealthcc.com/media/system/js/mootools-core.js | 200 OK Content-Length: 88540 Content-Type: application/x-javascript | clean |
http://summithealthcc.com/media/system/js/caption.js | 200 OK Content-Length: 800 Content-Type: application/x-javascript | clean |
http://summithealthcc.com/media/system/js/mootools-more.js | 200 OK Content-Length: 238128 Content-Type: application/x-javascript | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js | 200 OK Content-Length: 85925 Content-Type: text/javascript | clean |
http://summithealthcc.com/templates/realestatexl-tg/slideshow/jquery.aw-showcase.js | 200 OK Content-Length: 41145 Content-Type: application/x-javascript | clean |
http://summithealthcc.com/templates/realestatexl-tg/slideshow/settings.js | 200 OK Content-Length: 1541 Content-Type: application/x-javascript | clean |
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 6948 Content-Type: text/javascript | clean |
http://summithealthcc.com/index.php/sample-sites | 200 OK Content-Length: 20827 Content-Type: text/html | clean |
http://summithealthcc.com/index.php/site-map | 200 OK Content-Length: 20932 Content-Type: text/html | clean |
http://summithealthcc.com/index.php/using-joomla | 200 OK Content-Length: 21651 Content-Type: text/html | clean |
http://summithealthcc.com/index.php/using-joomla/extensions/components/content-component/article-category-list/8-beginners | 200 OK Content-Length: 26274 Content-Type: text/html | clean |
http://summithealthcc.com/index.php/using-joomla/extensions/components/content-component/article-category-list/69-professionals-2 | 200 OK Content-Length: 21769 Content-Type: text/html | clean |
http://summithealthcc.com/index.php/using-joomla/getting-help | 200 OK Content-Length: 21647 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: summithealthcc.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Wed, 06 Aug 2014 04:02:19 GMT
Pragma: no-cache
Accept-Ranges: bytes
Age: 0
Server: Apache/2
Content-Length: 19784
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 356b88306822062217d8888b646cfa2d=a1939ddc68c9f990e9f595aad57cddf7; path=/
X-Powered-By: PHP/5.3.13
...19784 bytes of data.
GET / HTTP/1.1
Host: summithealthcc.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Wed, 06 Aug 2014 04:02:19 GMT
Pragma: no-cache
Accept-Ranges: bytes
Age: 0
Server: Apache/2
Content-Length: 19784
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 356b88306822062217d8888b646cfa2d=a1939ddc68c9f990e9f595aad57cddf7; path=/
X-Powered-By: PHP/5.3.13
...19784 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: summithealthcc.com
Referer: http://www.google.com/search?q=summithealthcc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: summithealthcc.com
Referer: http://www.google.com/search?q=summithealthcc.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=summithealthcc.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://summithealthcc.com/
Result: summithealthcc.com is not infected or malware details are not published yet.
Result: summithealthcc.com is not infected or malware details are not published yet.