Scanned pages/files
Request | Server response | Status |
http://sym-baby.com/ | 200 OK Content-Length: 18504 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by Krad Xin | BD GREY HAT HACKERS <!DOCTYPE html>
<html dir="ltr" lang="ja" class="no-js"> <head> <meta charset="UTF-7" /> <meta name="viewport" content="width=device-width" /> <title>Hacked by Krad Xin | BD GREY HAT HACKERS</title> <link rel="profile" href="http://gmpg.org/xfn/11" /> <link rel="pingback" href="http://sym-baby.com/xmlrpc.php" /> <link rel="alternate" type="application/rss+xml" title="Hacked by Krad Xin » ãã£ã¼ã" href="http://sym-baby.com/?feed=rss2" /> <link rel="alternate" type="application/rss+xml" title="Hacked by Krad Xin » ã³ã¡ã³ãã㣠...[21760 bytes skipped]... | ||
http://sym-baby.com/wp-includes/js/jquery/jquery.js?ver=1.7.2 | 200 OK Content-Length: 94861 Content-Type: application/x-javascript | clean |
http://sym-baby.com/wp-content/themes/pinblue/library/js/modernizr-2.6.1.min.js?ver=2.6.1 | 200 OK Content-Length: 14414 Content-Type: application/x-javascript | clean |
http://sym-baby.com/wp-content/themes/pinblue/library/js/jquery.masonry.min.js?ver=3.4.2 | 200 OK Content-Length: 5476 Content-Type: application/x-javascript | clean |
http://sym-baby.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.18 | 200 OK Content-Length: 15021 Content-Type: application/x-javascript | clean |
http://sym-baby.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.3.1 | 200 OK Content-Length: 6859 Content-Type: application/x-javascript | clean |
http://sym-baby.com/wp-content/themes/pinblue/library/js/scripts.js?ver=1.0.0 | 200 OK Content-Length: 223 Content-Type: application/x-javascript | clean |
http://sym-baby.com/product | 200 OK Content-Length: 6945 Content-Type: text/html | clean |
http://sym-baby.com/wp-includes/js/comment-reply.js?ver=3.4.2 | 200 OK Content-Length: 786 Content-Type: application/x-javascript | clean |
http://sym-baby.com/contact | 200 OK Content-Length: 6149 Content-Type: text/html | clean |
http://sym-baby.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 17 Nov 2015 03:49:20 GMT Location: http://sym-baby.com/test404page.js/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-7 X-Pingback: http://sym-baby.com/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://sym-baby.com/test404page.js/ | 200 OK Content-Length: 18504 Content-Type: text/html | clean |
http://sym-baby.com/%2A11 | 200 OK Content-Length: 5926 Content-Type: text/html | clean |
http://sym-baby.com/?author=1 | 200 OK Content-Length: 18696 Content-Type: text/html | clean |
http://sym-baby.com/?cat=8 | 200 OK Content-Length: 9413 Content-Type: text/html | clean |
http://sym-baby.com/%2A09 | 200 OK Content-Length: 6111 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sym-baby.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 17 Nov 2015 03:49:09 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
X-Pingback: http://sym-baby.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: sym-baby.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 17 Nov 2015 03:49:09 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-7
X-Pingback: http://sym-baby.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: sym-baby.com
Referer: http://www.google.com/search?q=sym-baby.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sym-baby.com
Referer: http://www.google.com/search?q=sym-baby.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sym-baby.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sym-baby.com/
Result: sym-baby.com is not infected or malware details are not published yet.
Result: sym-baby.com is not infected or malware details are not published yet.