Scanned pages/files
Request | Server response | Status |
http://tiklalondra.com/ | 200 OK Content-Length: 10881 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Website Hacked by Cyb3R Sw0rD. <!DOCTYPE html> <html> <head> <title>Cyb3R Sw0rD</title> <link rel="SHORTCUT ICON" href="http://s12.postimg.org/tuv5l5p31/360x630_profile_logo.png" type="image/gif"> <meta charset="UTF-8"> <meta name="Author" content="Cyb3rGhOst"/> <meta name="copyright" content="Cyb3R Sw0rD"/> <meta name="description" content="Website Hacked by Cyb3R Sw0rD."/> <link href='http://fonts.googleapis.com/css?family=Iceland:400,700' rel='stylesheet' type='text/css'> <link href='http://fonts.googleapis.com/css?family=Iceland:400,700' rel='stylesheet' type='text/css'> <meta property="og:image" content=""> <iframe width="1" height="1" src="https://www.youtube.com/v/40DT4CEY0HY&autoplay=1" frameborder="0" allowfullscreen></iframe ...[12705 bytes skipped]... | ||
http://code.jquery.com/jquery.min.js | 200 OK Content-Length: 95821 Content-Type: application/x-javascript | clean |
http://tiklalondra.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Fri, 06 Mar 2015 14:56:13 GMT Location: https://50webs.biz/404/ Server: Apache mod_fcgid/2.3.7 mod_auth_pgsql/2.0.3 Vary: Accept-Encoding Content-Length: 207 Content-Type: text/html; charset=iso-8859-1 | clean |
https://50webs.biz/404/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Fri, 06 Mar 2015 14:56:13 GMT Pragma: no-cache Location: /login/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: WHCP=i5n6bedk90c7bjai6308q1joa0; path=/ X-Powered-By: PHP/5.4.36-0+deb7u3 | clean |
https://50webs.biz/login/ | 200 OK Content-Length: 5353 Content-Type: text/html | clean |
https://50webs.biz/js/jses.min.js?v=1425642448 | 200 OK Content-Length: 303104 Content-Type: application/javascript | clean |
http://tiklalondra.com/js/jquery_plugins/jquery-fonteffect-1.0.0.min.js | HTTP/1.1 302 Found Connection: close Date: Fri, 06 Mar 2015 14:56:17 GMT Location: https://50webs.biz/404/ Server: Apache mod_fcgid/2.3.7 mod_auth_pgsql/2.0.3 Vary: Accept-Encoding Content-Length: 207 Content-Type: text/html; charset=iso-8859-1 | clean |
http://50webs.biz/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:18 GMT Location: http://us.cloudlogin.co//test404page.js Server: Apache Vary: Accept-Encoding Content-Length: 307 Content-Type: text/html; charset=iso-8859-1 | clean |
http://us.cloudlogin.co//test404page.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:18 GMT Location: https://us.cloudlogin.co/test404page.js/ Server: Apache Vary: Accept-Encoding Content-Length: 314 Content-Type: text/html; charset=iso-8859-1 | clean |
https://us.cloudlogin.co/test404page.js/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Fri, 06 Mar 2015 14:56:19 GMT Pragma: no-cache Location: /login/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: WHCP=i4f9pq6orp2bt37c5krfcet5t6; path=/ X-Powered-By: PHP/5.4.36-0+deb7u3 | clean |
https://us.cloudlogin.co/login/ | 200 OK Content-Length: 6444 Content-Type: text/html | clean |
https://us.cloudlogin.co/js/jses.min.js?v=1425642448 | 200 OK Content-Length: 303104 Content-Type: application/javascript | clean |
http://50webs.biz/js/jquery_plugins/jquery-fonteffect-1.0.0.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:23 GMT Location: http://us.cloudlogin.co//js/jquery_plugins/jquery-fonteffect-1.0.0.min.js Server: Apache Vary: Accept-Encoding Content-Length: 341 Content-Type: text/html; charset=iso-8859-1 | clean |
http://us.cloudlogin.co//js/jquery_plugins/jquery-fonteffect-1.0.0.min.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:23 GMT Location: https://us.cloudlogin.co/js/jquery_plugins/jquery-fonteffect-1.0.0.min.js/ Server: Apache Vary: Accept-Encoding Content-Length: 348 Content-Type: text/html; charset=iso-8859-1 | clean |
https://us.cloudlogin.co/js/jquery_plugins/jquery-fonteffect-1.0.0.min.js/ | 404 Not Found Content-Length: 314 Content-Type: text/html | clean |
http://us.cloudlogin.co/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:24 GMT Location: https://us.cloudlogin.co/test404page.js Server: Apache Vary: Accept-Encoding Content-Length: 313 Content-Type: text/html; charset=iso-8859-1 | clean |
https://us.cloudlogin.co/test404page.js | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Fri, 06 Mar 2015 14:56:25 GMT Pragma: no-cache Location: /login/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: WHCP=8gs2h6c5qmpgpp2ltp1ldcuru6; path=/ X-Powered-By: PHP/5.4.36-0+deb7u3 | clean |
http://50webs.biz/js/video-js/video.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:25 GMT Location: http://us.cloudlogin.co//js/video-js/video.min.js Server: Apache Vary: Accept-Encoding Content-Length: 317 Content-Type: text/html; charset=iso-8859-1 | clean |
http://us.cloudlogin.co//js/video-js/video.min.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 14:56:26 GMT Location: https://us.cloudlogin.co/js/video-js/video.min.js/ Server: Apache Vary: Accept-Encoding Content-Length: 324 Content-Type: text/html; charset=iso-8859-1 X-Pad: avoid browser bug | clean |
https://us.cloudlogin.co/js/video-js/video.min.js/ | 404 Not Found Content-Length: 290 Content-Type: text/html | clean |
https://www.corecounter.net/counter.php?user=59 | 200 OK Content-Length: 482 Content-Type: text/html | clean |
http://tiklalondra.com/js/video-js/video.min.js | HTTP/1.1 302 Found Connection: close Date: Fri, 06 Mar 2015 14:56:28 GMT Location: https://50webs.biz/404/ Server: Apache mod_fcgid/2.3.7 mod_auth_pgsql/2.0.3 Vary: Accept-Encoding Content-Length: 207 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tiklalondra.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 06 Mar 2015 14:56:12 GMT
Pragma: no-cache
Server: Apache mod_fcgid/2.3.7 mod_auth_pgsql/2.0.3
Vary: User-Agent,Accept-Encoding
Content-Length: 10881
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=e4kregbj50l9kl9os874fsfbh0; path=/
X-Powered-By: PHP/5.4.34
...10881 bytes of data.
GET / HTTP/1.1
Host: tiklalondra.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 06 Mar 2015 14:56:12 GMT
Pragma: no-cache
Server: Apache mod_fcgid/2.3.7 mod_auth_pgsql/2.0.3
Vary: User-Agent,Accept-Encoding
Content-Length: 10881
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=e4kregbj50l9kl9os874fsfbh0; path=/
X-Powered-By: PHP/5.4.34
...10881 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tiklalondra.com
Referer: http://www.google.com/search?q=tiklalondra.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tiklalondra.com
Referer: http://www.google.com/search?q=tiklalondra.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tiklalondra.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tiklalondra.com/
Result: tiklalondra.com is not infected or malware details are not published yet.
Result: tiklalondra.com is not infected or malware details are not published yet.