Scanned pages/files
Request | Server response | Status |
http://theolivetreestudios.com/ | 200 OK Content-Length: 23721 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked by AlfabetoVirtual ...[9073 bytes skipped]... is).children("img").attr("title"); jQuery(this).attr('title',title); }) } // Supported file extensions var thumbnails = jQuery("a:has(img)").not(".nolightbox").filter( function() { return /\.(jpe?g|png|gif|bmp)$/i.test(jQuery(this).attr('href')) }); jQuery("a.fancybox").fancybox({ 'cyclic': false, 'autoScale': false, 'padding': </script><script>document.title = 'Hacked by AlfabetoVirtual';</script><style>body {font-family: Times New Roman, cursive, sans-serif;background-color: #000000;color:white; text-shadow:0 0 60px black;font-size:20px;}</style><center><br /><br /><br /><br /><br /><br /><h1>Hacked by AlfabetoVirtual</h1><h2 style='color: white'>Hackeado por AlfabetoVirtual</h2>#BrazilUnderground #HackersBrasileirosUnidos #AntiGovernoBR</center><!--Hackedddd ...[17957 bytes skipped]... | ||
http://theolivetreestudios.com/wp-includes/js/jquery/jquery.js?ver=1.7.2 | 200 OK Content-Length: 94861 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/plugins/anti-spam/js/anti-spam.js?ver=1.9 | 200 OK Content-Length: 1696 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/library/tfuse_framework/js/sendmail.js?ver=1.1 | 200 OK Content-Length: 3043 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-includes/js/comment-reply.js?ver=5902 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/plugins/fancybox-for-wordpress/fancybox/jquery.fancybox.js?ver=1.3.4 | 200 OK Content-Length: 15622 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/plugins/flash-gallery/js/addOnLoad.js?ver=1 | 200 OK Content-Length: 704 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/general.js?ver=5902 | 200 OK Content-Length: 2228 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/jquery.easing.1.3.js?ver=5902 | 200 OK Content-Length: 4824 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/slides.jquery.js?ver=5902 | 200 OK Content-Length: 17147 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/jquery-ui-1.8.4.custom.min.js?ver=5902 | 200 OK Content-Length: 12734 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/jquery-ui-1.8.9.custom.min.js?ver=5902 | 200 OK Content-Length: 210463 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/ui.selectmenu.js?ver=5902 | 200 OK Content-Length: 16470 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/styled.selectmenu.js?ver=5902 | 200 OK Content-Length: 850 Content-Type: application/javascript | clean |
http://theolivetreestudios.com/wp-content/themes/welcome_inn/js/custom.js?ver=5902 | 200 OK Content-Length: 86 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: theolivetreestudios.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 30 Jul 2015 18:01:07 GMT
Server: Apache
Vary: Cookie
Content-Length: 23721
Content-Type: text/html; charset=UTF-8
Expires: Thu, 30 Jul 2015 18:21:07 GMT
Last-Modified: Thu, 30 Jul 2015 18:01:07 GMT
X-Pingback: http://theolivetreestudios.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.2.4
...23721 bytes of data.
GET / HTTP/1.1
Host: theolivetreestudios.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 30 Jul 2015 18:01:07 GMT
Server: Apache
Vary: Cookie
Content-Length: 23721
Content-Type: text/html; charset=UTF-8
Expires: Thu, 30 Jul 2015 18:21:07 GMT
Last-Modified: Thu, 30 Jul 2015 18:01:07 GMT
X-Pingback: http://theolivetreestudios.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.2.4
...23721 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: theolivetreestudios.com
Referer: http://www.google.com/search?q=theolivetreestudios.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: theolivetreestudios.com
Referer: http://www.google.com/search?q=theolivetreestudios.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=theolivetreestudios.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://theolivetreestudios.com/
Result: theolivetreestudios.com is not infected or malware details are not published yet.
Result: theolivetreestudios.com is not infected or malware details are not published yet.