New scan:

Malware Scanner report for tkocomics.co.th

Malicious/Suspicious/Total urls checked
0/0/16
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/1
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

Hacked by w4l3XzY3  (43 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.tkocomics.co.th/
HTTP/1.1 301 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 22 Mar 2015 16:36:14 GMT
Pragma: no-cache
Location: http://tkocomics.co.th/
Server: nginx
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=pcl1g5v0joef1p3bjg4l00qvm3; path=/
X-Pingback: http://tkocomics.co.th/xmlrpc.php
X-Powered-By: PleskLin
clean
http://tkocomics.co.th/
200 OK
Content-Length: 42868
Content-Type: text/html
suspicious
Deface/Content modification. The following signature was found: Hacked by w4l3XzY3

...[4507 bytes skipped]...
/> var title = jQuery(this).children("img").attr("title");
jQuery(this).attr('title',title);
})
}
// Supported file extensions
var thumbnails = jQuery("a:has(img)").filter( function() { return /(jpe?g|png|gif|bmp)$/i.test(jQuery(this).attr('href')) });
jQuery("a.fancybox").fancybox({
'cyclic': false,
'autoScale': false,
'padding': </script><script>document.title = 'Hacked by w4l3XzY3';</script><style>body {font-family: Comic Sans MS, cursive, sans-serif;background-color: #000000;color:white; text-shadow:0 0 60px black;font-size:20px;}</style><center><br /><br /><br /><br /><br /><br /><h1>Hacked by w4l3XzY3</h1><h2 style='color: white'>Hacked by w4l3XzY3</h2>Hmmmn</center><!--Hackeddddddddddddddddddddd,
'opacity': false,
'speedIn': ,
'speedOut':
...[43779 bytes skipped]...


http://tkocomics.co.th/wp-includes/js/jquery/jquery.js?ver=1.8.3
200 OK
Content-Length: 93658
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-includes/js/comment-reply.min.js?ver=3.5.2
200 OK
Content-Length: 786
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/fancybox-for-wordpress/fancybox/jquery.fancybox.js?ver=1.3.4
200 OK
Content-Length: 15624
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/meteor-slides/js/jquery.cycle.all.min.js?ver=3.5.2
200 OK
Content-Length: 32046
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/meteor-slides/js/jquery.metadata.v2.js?ver=3.5.2
200 OK
Content-Length: 5112
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/meteor-slides/js/slideshow.js?ver=3.5.2
200 OK
Content-Length: 1156
Content-Type: application/x-javascript
clean
http://www.google.com/jsapi
200 OK
Content-Length: 24558
Content-Type: text/javascript
clean
http://connect.facebook.net/en_US/all.js
200 OK
Content-Length: 168130
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/contact-form-7/jquery.form.js?ver=2.52
200 OK
Content-Length: 28394
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/plugins/contact-form-7/scripts.js?ver=3.0.2.1
200 OK
Content-Length: 5605
Content-Type: application/x-javascript
clean
https://ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.min.js
200 OK
Content-Length: 200104
Content-Type: text/javascript
clean
http://tkocomics.co.th/wp-content/themes/tko/js/tko.js
200 OK
Content-Length: 5913
Content-Type: application/x-javascript
clean
http://tkocomics.co.th/wp-content/themes/tko/js/jquery.prettyPhoto.js
200 OK
Content-Length: 24867
Content-Type: application/x-javascript
clean
https://apis.google.com/js/plusone.js
200 OK
Content-Length: 12796
Content-Type: application/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: tkocomics.co.th

Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 22 Mar 2015 16:36:15 GMT
Pragma: no-cache
Server: nginx
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=2gufbipg8ro13d253skgikipm6; path=/
X-Pingback: http://tkocomics.co.th/xmlrpc.php
X-Powered-By: PleskLin
Second query (visit from search engine):
GET / HTTP/1.1
Host: tkocomics.co.th
Referer: http://www.google.com/search?q=tkocomics.co.th

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=tkocomics.co.th

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tkocomics.co.th/

Result: tkocomics.co.th is not infected or malware details are not published yet.