Scanned pages/files
Request | Server response | Status |
http://trekkingexpeditor.com/ | 200 OK Content-Length: 9150 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Aung Lat ...[6429 bytes skipped]... th:60%; margin-left:20%; margin-top:10%; } </style> </head> <body onLoad="type_text(),writetext()"> <section id="matrix">Myanmar Muslim Cyber Force</section> <center><script language="JavaScript"> msg = new Array(); //strings written in screen msg[0] = "<h1><font face='Courier' color='#00FF00'><---==[<font face='Courier' color='red'> Hacked By Aung Lat <font face='Courier' color='#00FF00'>]==---</h1>"; text1 = ""; //the same as text2, only the last character is highlighted text2 = ""; //current string, which will be written count = 0; //char index in string text count2 = 10; //number of strings text = msg[0].split(""); //text - string written function writetext() { //show strings above on screen text1 = text2 + "<font color='#00FF00'>" + text[count] + "</font>"; text2 += text[count]; document.all[ ...[2330 bytes skipped]... | ||
http://trekkingexpeditor.com/test404page.js | 404 Not Found Content-Length: 595 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trekkingexpeditor.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 21 Oct 2014 23:28:28 GMT
Accept-Ranges: bytes
ETag: "58590c4-23be-505b981200040"
Server: Apache
Content-Length: 9150
Content-Type: text/html
Last-Modified: Sat, 18 Oct 2014 21:52:57 GMT
...9150 bytes of data.
GET / HTTP/1.1
Host: trekkingexpeditor.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 21 Oct 2014 23:28:28 GMT
Accept-Ranges: bytes
ETag: "58590c4-23be-505b981200040"
Server: Apache
Content-Length: 9150
Content-Type: text/html
Last-Modified: Sat, 18 Oct 2014 21:52:57 GMT
...9150 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: trekkingexpeditor.com
Referer: http://www.google.com/search?q=trekkingexpeditor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trekkingexpeditor.com
Referer: http://www.google.com/search?q=trekkingexpeditor.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trekkingexpeditor.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://trekkingexpeditor.com/
Result: trekkingexpeditor.com is not infected or malware details are not published yet.
Result: trekkingexpeditor.com is not infected or malware details are not published yet.