Scanned pages/files
Request | Server response | Status |
http://welcometonewport.org/ | 200 OK Content-Length: 740 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: HACKED By.. ...[111 bytes skipped]... t;body bgcolor="Black" text="Black"> <center>` <style type="text/css"> BODY { SCROLLBAR-FACE-COLOR: #000000; SCROLLBAR-HIGHLIGHT-COLOR: #000000; SCROLLBAR-SHADOW-COLOR: #000000; SCROLLBAR-BASE-COLOR: #000000; background-image: url(http://im27.gulfup.com/CHjL1.jpg); } </style> <font size="8" color="White">HACKED By..</font> <br> <br> <font size="20" color="Red">.:[ L0lz T3aM ]:.</font> <br> <br> <img src="http://www7.0zz0.com/2010/11/22/12/109217099.jpg"> <br><br> <font size="6" color="Red">#[ VeTo Ly & FLY BOY ]#</font> <br> <br> <img src="http://i708.photobucket.com/albums/ww84/achye/hacked.gif"> <br><br> </body> </htm | ||
http://welcometonewport.org/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: welcometonewport.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 01 Jun 2015 16:58:11 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
GET / HTTP/1.1
Host: welcometonewport.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 01 Jun 2015 16:58:11 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: welcometonewport.org
Referer: http://www.google.com/search?q=welcometonewport.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: welcometonewport.org
Referer: http://www.google.com/search?q=welcometonewport.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=welcometonewport.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://welcometonewport.org/
Result: welcometonewport.org is not infected or malware details are not published yet.
Result: welcometonewport.org is not infected or malware details are not published yet.