Scanned pages/files
Request | Server response | Status |
http://thermosanitdz.com/ | 200 OK Content-Length: 1999 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Synchronizer ...[482 bytes skipped]... tent="Synchronizer Was Fuck Your System !" /> <link rel="shortcut icon" href="http://uci-forum.ucoz.org/UCI_Gif.gif"> <body bgcolor='Black'> </head> <body> <link href='http://fonts.googleapis.com/css?family=Orbitron' rel='stylesheet' type='text/css'> <center><b><span style="font-family: Tahoma"><font size="7" face="Orbitron" color="#fff">Hacked By Synchronizer</font></span></b><br><br> <img alt="" src="http://uci-forum.ucoz.org/UCI_Gif.gif" height="300" width="300" ></div><p> <font face="Tahoma" size="2" color="grey"> <br><br> Upss.. <font color="#00ff00">Synchronizer</font> Was Here !<br><br><font color="yellow"> Just a Security reminder, Please improve your website security ^_^</font> <br><br>[#]<font ...[1067 bytes skipped]... | ||
http://blogskins.ir/tools/java/no-rightclick.js | 200 OK Content-Length: 443 Content-Type: application/javascript | clean |
http://blogskins.ir/tools/java/no-select.js | 200 OK Content-Length: 232 Content-Type: application/javascript | clean |
http://misbahudin-dcaesga.googlecode.com/files/efek-salju.js | 200 OK Content-Length: 15988 Content-Type: text/x-c++ | clean |
http://misbahudin-dcaesga.googlecode.com/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://misbahudin-dcaesga.googlecode.com//www.google.com/ | 404 Not Found Content-Length: 1425 Content-Type: text/html | clean |
http://thermosanitdz.com//www.google.com/ | 404 Not Found Content-Length: 332 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thermosanitdz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 26 Feb 2015 19:11:26 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1999
Content-Type: text/html
Last-Modified: Fri, 06 Feb 2015 20:41:47 GMT
...1999 bytes of data.
GET / HTTP/1.1
Host: thermosanitdz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 26 Feb 2015 19:11:26 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1999
Content-Type: text/html
Last-Modified: Fri, 06 Feb 2015 20:41:47 GMT
...1999 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: thermosanitdz.com
Referer: http://www.google.com/search?q=thermosanitdz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thermosanitdz.com
Referer: http://www.google.com/search?q=thermosanitdz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thermosanitdz.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://thermosanitdz.com/
Result: thermosanitdz.com is not infected or malware details are not published yet.
Result: thermosanitdz.com is not infected or malware details are not published yet.