Scanned pages/files
Request | Server response | Status |
http://wifithankyou.com/ | 200 OK Content-Length: 18853 Content-Type: text/html | suspicious |
Suspicious code found <div id="main"> <!--main-in--> <div id="main-in"> <!--â½ã¡ã¤ã³ã³ã³ãã³ã--> <div id="main-contents"> <!--ææ°æ å ±--> <h2>ææ°æ å ±</h2> <div class="contents"> <dl class="news"> <dt>2013å¹´9æ14æ¥<span class="color01 category01">æ¥è¨</span></dt><dd><a href="http://wifithankyou.com/11.html" title="ã¿ãã¬ãããå©ç¨ããå¾ã§ã¯ãã©ã·ãã </ul> <!--/ããã¿ã¼ããã¼--> <!--ã³ãã¼ã©ã¤ã--> <p class="copyright"><small>Copyright (C) 2012 All Rights Reserved.</small></p> <!--/ã³ãã¼ã©ã¤ã--> <!--copyright--> <!--ãã®è¡ã¯åé¤ããªãã§ãã ããã--> <!--/ãã®è¡ã¯åé¤ããªãã§ãã ããã--> </div> </div> <!--â³ããã¿ã¼:footer.phpãç·¨é--> </div> | ||
http://www.google.com/jsapi | 200 OK Content-Length: 25240 Content-Type: text/javascript | clean |
http://wifithankyou.com/wp-content/themes/KENI-WP2/js/rollover.js | 200 OK Content-Length: 284 Content-Type: application/javascript | clean |
http://wifithankyou.com/?sitemap | 200 OK Content-Length: 8601 Content-Type: text/html | suspicious |
Suspicious code found <div id="main"> <!--main-in--> <div id="main-in"> <!--â½ã¡ã¤ã³ã³ã³ãã³ã--> <div id="main-contents"> <h2>ãµã¤ãããã</h2> <div class="contents"> <ul class="sitemap"> <li><a href="http://wifithankyou.com">ï¼ï¼ä»£å¥³æ師ã®ã¡ãã£ã¨æ°ã«ãªãå£èäºé²æ¹æ³</a></li> <li> </li> <li>ããã°è¨äº <ul><li><a h </ul> <!--/ããã¿ã¼ããã¼--> <!--ã³ãã¼ã©ã¤ã--> <p class="copyright"><small>Copyright (C) 2012 All Rights Reserved.</small></p> <!--/ã³ãã¼ã©ã¤ã--> <!--copyright--> <!--ãã®è¡ã¯åé¤ããªãã§ãã ããã--> <!--/ãã®è¡ã¯åé¤ããªãã§ãã ããã--> </div> </div> <!--â³ããã¿ã¼:footer.phpãç·¨é--> </div> | ||
http://wifithankyou.com/test404page.js | 404 Not Found Content-Length: 9428 Content-Type: text/html | suspicious |
Suspicious code found <div id="main"> <!--main-in--> <div id="main-in"> <!--â½ã¡ã¤ã³ã³ã³ãã³ã--> <div id="main-contents"> <h2>ãã¼ã¸ãè¦ã¤ããã¾ããã§ããã</h2> <div class="contents"> <p><a href="http://wifithankyou.com">ï¼ï¼ä»£å¥³æ師ã®ã¡ãã£ã¨æ°ã«ãªãå£èäºé²æ¹æ³</a>ã«æ»ã</p> </div> <!--ææ°æ å ±--> <h2>ææ°æ å ±</h2> < </ul> <!--/ããã¿ã¼ããã¼--> <!--ã³ãã¼ã©ã¤ã--> <p class="copyright"><small>Copyright (C) 2012 All Rights Reserved.</small></p> <!--/ã³ãã¼ã©ã¤ã--> <!--copyright--> <!--ãã®è¡ã¯åé¤ããªãã§ãã ããã--> <!--/ãã®è¡ã¯åé¤ããªãã§ãã ããã--> </div> </div> <!--â³ããã¿ã¼:footer.phpãç·¨é--> </div> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: wifithankyou.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 Oct 2015 03:03:35 GMT
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Type: text/html; charset=UTF-8
X-Pingback: http://wifithankyou.com/xmlrpc.php
X-Powered-By: PHP/5.3.17
GET / HTTP/1.1
Host: wifithankyou.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 Oct 2015 03:03:35 GMT
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Type: text/html; charset=UTF-8
X-Pingback: http://wifithankyou.com/xmlrpc.php
X-Powered-By: PHP/5.3.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: wifithankyou.com
Referer: http://www.google.com/search?q=wifithankyou.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: wifithankyou.com
Referer: http://www.google.com/search?q=wifithankyou.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=wifithankyou.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://wifithankyou.com/
Result: wifithankyou.com is not infected or malware details are not published yet.
Result: wifithankyou.com is not infected or malware details are not published yet.