New scan:

Malware Scanner report for whatuptucson.com

Malicious/Suspicious/Total urls checked
0/0/3
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

Hacked By MoHaMaD VaKeR  (3 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://whatuptucson.com/
HTTP/1.1 302 Found
Connection: close
Date: Thu, 10 Apr 2014 19:17:07 GMT
Location: http://whatuptucson.com/503.php
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 393
Content-Type: text/html; charset=iso-8859-1
clean
http://whatuptucson.com/503.php
200 OK
Content-Length: 2095
Content-Type: text/html
suspicious
Deface/Content modification. The following signature was found: Hacked By MoHaMaD VaKeR

...[1663 bytes skipped]...
CROLLBAR-BASE-COLOR: #000000
}
</style>

<style fprolloverstyle="">
TEXTAREA {
BORDER-LEFT-COLOR: #000000; BACKGROUND: #000000; BORDER-BOTTOM-COLOR: #000000; FONT: 12px Verdana, Verdana, Verdana, Verdana; COLOR: #d3d3d3; BORDER-TOP-COLOR: #000000; BORDER-RIGHT-COLOR: #000000
}
</style>

<h2><font color="#cecece" face="Caurier" size="12">Hacked By MoHaMaD VaKeR</font></h2>
<form><font color="#ff0000">
<textarea rows="18" cols="90" readonly="readonly"></textarea>

</font></form>
<br><font color="grey" size=1 face="Verdana, Arial, Helvetica, sans-serif"><Hmei7></font>
</div>
</body>

<!-- BUNDA6 | mami 5 | English (United States) | 12/13/2010 9:08:53 AM --> 1


http://whatuptucson.com/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Thu, 10 Apr 2014 19:17:08 GMT
Location: http://whatuptucson.com/503.php
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 393
Content-Type: text/html; charset=iso-8859-1
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: whatuptucson.com

Result:
HTTP/1.1 302 Found
Connection: close
Date: Thu, 10 Apr 2014 19:17:07 GMT
Location: http://whatuptucson.com/503.php
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 393
Content-Type: text/html; charset=iso-8859-1

...393 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: whatuptucson.com
Referer: http://www.google.com/search?q=whatuptucson.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=whatuptucson.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://whatuptucson.com/

Result: whatuptucson.com is not infected or malware details are not published yet.