Scanned pages/files
Request | Server response | Status |
http://threadboutique.sg/ | 200 OK Content-Length: 2222 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HackeD by KeyLo99 <body bgcolor=black>
<a>title= "HackeD by KeyLo99" width=200" height="150" align="left"><center><img src="http://i.hizliresim.com/rQZqbM.png" alt="KeyLo99" width="128" height="166" align="align"></a></center> <center><b><font size="7"><font color=DarkOrange>~HackeD by KeyLo99~</font></font></b></center> <center><b><font size="5"><font color=DarkOrange>-------------------- ...[2471 bytes skipped]... | ||
http://threadboutique.sg/test404page.js | 404 Not Found Content-Length: 40867 Content-Type: text/html | clean |
http://www.c99txt.net/siyir/cookie.js | 200 OK Content-Length: 90 Content-Type: application/javascript | clean |
http://threadboutique.sg/? | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=phpinfo | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2F&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2Fhome%2F&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2Fhome%2Fnorthpa2%2F&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2F&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2Fwww.threadboutique.sg%2F&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=ls&d=%2Fhome%2Fnorthpa2%2Fpublic_html&sort=0a | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=search&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2Fwww.threadboutique.sg%2F | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=fsbuff&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2Fwww.threadboutique.sg%2F | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=encoder&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2Fwww.threadboutique.sg%2F | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
http://threadboutique.sg/?act=bind&d=%2Fhome%2Fnorthpa2%2Fpublic_html%2Fwww.threadboutique.sg%2F | 200 OK Content-Length: 2222 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: threadboutique.sg
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 15 Oct 2015 20:49:25 GMT
Server: Apache/2.4.12 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 2222
Content-Type: text/html; charset=UTF-8
X-Pingback: http://threadboutique.sg/xmlrpc.php
X-Powered-By: PHP/5.4.45
...2222 bytes of data.
GET / HTTP/1.1
Host: threadboutique.sg
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 15 Oct 2015 20:49:25 GMT
Server: Apache/2.4.12 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Content-Length: 2222
Content-Type: text/html; charset=UTF-8
X-Pingback: http://threadboutique.sg/xmlrpc.php
X-Powered-By: PHP/5.4.45
...2222 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: threadboutique.sg
Referer: http://www.google.com/search?q=threadboutique.sg
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: threadboutique.sg
Referer: http://www.google.com/search?q=threadboutique.sg
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=threadboutique.sg
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://threadboutique.sg/
Result: threadboutique.sg is not infected or malware details are not published yet.
Result: threadboutique.sg is not infected or malware details are not published yet.