Scanned pages/files
Request | Server response | Status |
http://texasholdemsites.com/ | 200 OK Content-Length: 3210 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By darkshadow-tn <TITLE>Hacked By darkshadow-tn</TITLE> <title>Hacked By AnonCoders</title> <META NAME="keywords" CONTENT="Hacked By AnonCoders"> </head> <!-----------Powered--By----AnonCoders---------> <body> <div align="center"> <tr> <div class="miniblock"><font face="cursive" size="4"><b> <style type="text/css"> body{font-weight: normal ...[3352 bytes skipped]... | ||
http://texasholdemsites.com/test404page.js | 404 Not Found Content-Length: 9605 Content-Type: text/html | clean |
http://texasholdemsites.com/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/jquery.bxslider.min.js?ver=4.1.7 | 200 OK Content-Length: 19359 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/fitvids.js?ver=4.1.7 | 200 OK Content-Length: 2663 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/jquery.slicknav.min.js?ver=4.1.7 | 200 OK Content-Length: 6301 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/owl.carousel.min.js?ver=4.1.7 | 200 OK Content-Length: 23890 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/retina.min.js?ver=4.1.7 | 200 OK Content-Length: 2575 Content-Type: application/javascript | clean |
http://texasholdemsites.com/wp-content/themes/hemlock/hemlock/js/solopine.js?ver=4.1.7 | 200 OK Content-Length: 939 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: texasholdemsites.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 16 Aug 2015 08:41:20 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4
Content-Type: text/html; charset=UTF-7
X-Pingback: http://texasholdemsites.com/xmlrpc.php
X-Powered-By: PHP/5.3.10
GET / HTTP/1.1
Host: texasholdemsites.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 16 Aug 2015 08:41:20 GMT
Server: Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_bwlimited/1.4
Content-Type: text/html; charset=UTF-7
X-Pingback: http://texasholdemsites.com/xmlrpc.php
X-Powered-By: PHP/5.3.10
Second query (visit from search engine):
GET / HTTP/1.1
Host: texasholdemsites.com
Referer: http://www.google.com/search?q=texasholdemsites.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: texasholdemsites.com
Referer: http://www.google.com/search?q=texasholdemsites.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=texasholdemsites.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://texasholdemsites.com/
Result: texasholdemsites.com is not infected or malware details are not published yet.
Result: texasholdemsites.com is not infected or malware details are not published yet.