Scanned pages/files
Request | Server response | Status |
http://tiemannphoto.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Apr 2014 18:14:10 GMT Location: http://www.tiemannphoto.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-7 X-Pingback: http://www.tiemannphoto.com/xmlrpc.php X-Powered-By: PHP/5.4.23 | clean |
http://www.tiemannphoto.com/ | 200 OK Content-Length: 17445 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: +ADw-html+AD4APA-head+AD4APA-title+AD4-hacked by mustireiS+ADw-/title+AD4 ...[502 bytes skipped]... "profile" href="http://gmpg.org/xfn/11" /> <link rel="pingback" href="http://www.tiemannphoto.com/xmlrpc.php" /> <!--[if lt IE 9]> <script src="http://www.tiemannphoto.com/wp-content/themes/twentytwelve/js/html5.js" type="text/javascript"></script> <![endif]--> <link rel="alternate" type="application/rss+xml" title="+ADw-/title+AD4 +ADw-html+AD4APA-head+AD4APA-title+AD4-hacked by mustireiS+ADw-/title+AD4 +ADw-/head+AD4APA-body+AD4APA-center+AD4-Hacked By +ADw-strong+AD4-mustireiS+ADw-/strong+AD4APA-/center+AD4APA-br+AD4APA-center+AD4-kopirayt 2009 +ACE +ADw-/center+AD4 +ADw-/body+AD4APA-br+AD4APA-center+AD4APA-strong+AD4APA-/strong+AD4 +ADw-iframe width+AD0AIg-1+ACI height+AD0AIg-1+ACI src+AD0AIg-http://www.youtube.com/embed/cdPh4XColLA?+ACY-amp+ADs-autoplay+AD0-1+ACI frameborder+AD0AIg-0+ACI allowfullscreen+AD0AIgAiAD4APA ...[18189 bytes skipped]... | ||
http://www.tiemannphoto.com/wp-content/themes/twentytwelve/js/navigation.js?ver=1.0 | 200 OK Content-Length: 863 Content-Type: application/javascript | clean |
http://tiemannphoto.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Apr 2014 18:14:13 GMT Location: http://www.tiemannphoto.com Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-7 X-Pingback: http://www.tiemannphoto.com/xmlrpc.php X-Powered-By: PHP/5.4.23 | clean |
http://www.tiemannphoto.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 18 Apr 2014 18:14:13 GMT Location: http://www.tiemannphoto.com Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-7 X-Pingback: http://www.tiemannphoto.com/xmlrpc.php X-Powered-By: PHP/5.4.23 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tiemannphoto.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 18 Apr 2014 18:14:10 GMT
Location: http://www.tiemannphoto.com/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-7
X-Pingback: http://www.tiemannphoto.com/xmlrpc.php
X-Powered-By: PHP/5.4.23
...0 bytes of data.
GET / HTTP/1.1
Host: tiemannphoto.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 18 Apr 2014 18:14:10 GMT
Location: http://www.tiemannphoto.com/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-7
X-Pingback: http://www.tiemannphoto.com/xmlrpc.php
X-Powered-By: PHP/5.4.23
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tiemannphoto.com
Referer: http://www.google.com/search?q=tiemannphoto.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tiemannphoto.com
Referer: http://www.google.com/search?q=tiemannphoto.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tiemannphoto.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tiemannphoto.com/
Result: tiemannphoto.com is not infected or malware details are not published yet.
Result: tiemannphoto.com is not infected or malware details are not published yet.