Scanned pages/files
Request | Server response | Status |
http://worldtradebook.com/ | 200 OK Content-Length: 3351 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By_yskr <html dir="rtl"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <meta http-equiv="Content-Language" content="TR"/> <title>Hacked By_yskr</title> <meta name="keywords" content="Hacked By_yskr"> <meta name="description" content="Hacked By_yskr"> </head> <embed src="https://www.youtube.com/v/Mj6tFXJUuls&autoplay=1?version=3&autoplay=1&feature=player_detailpage" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="1" width="1"></object> <body ...[3328 bytes skipped]... | ||
http://worldtradebook.com/test404page.js | 404 Not Found Content-Length: 43220 Content-Type: text/html | clean |
http://worldtradebook.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://worldtradebook.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://worldtradebook.com/wp-content/themes/GeoTheme/library/js/custom.js?ver=3.8.7 | 200 OK Content-Length: 54700 Content-Type: application/javascript | clean |
http://maps.google.com/maps/api/js?sensor=false | 200 OK Content-Length: 4415 Content-Type: text/javascript | clean |
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12785 Content-Type: application/javascript | clean |
http://gmaps-samples-v3.googlecode.com/svn/trunk/geolocate/geometa.js | 200 OK Content-Length: 6461 Content-Type: text/javascript | clean |
https://checkout.google.com/buttons/logos?merchant_id=415650825885290&loc=en&f=png | 404 Not Found Content-Length: 1487 Content-Type: text/html | clean |
https://checkout.google.com//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://checkout.google.com/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://checkout.google.com//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://worldtradebook.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.48.0-2013.12.28 | 200 OK Content-Length: 15054 Content-Type: application/javascript | clean |
http://worldtradebook.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.7 | 200 OK Content-Length: 8913 Content-Type: application/javascript | clean |
https://seal.godaddy.com/getSeal?sealID=86LfdFcfKFK0z9jCXcsHnAtIWLkOB2xbAu86Z40HFzydubtr2oCsnwyz | 204 No Content Content-Length: 0 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: worldtradebook.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 01 May 2015 11:28:32 GMT
Pragma: no-cache
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b6783f6b32eededec3a481566498b7db; path=/
X-Pingback: http://worldtradebook.com/xmlrpc.php
X-Powered-By: PHP/5.4.21
GET / HTTP/1.1
Host: worldtradebook.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 01 May 2015 11:28:32 GMT
Pragma: no-cache
Server: Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4
Content-Type: text/html; charset=UTF-7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=b6783f6b32eededec3a481566498b7db; path=/
X-Pingback: http://worldtradebook.com/xmlrpc.php
X-Powered-By: PHP/5.4.21
Second query (visit from search engine):
GET / HTTP/1.1
Host: worldtradebook.com
Referer: http://www.google.com/search?q=worldtradebook.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: worldtradebook.com
Referer: http://www.google.com/search?q=worldtradebook.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=worldtradebook.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://worldtradebook.com/
Result: worldtradebook.com is not infected or malware details are not published yet.
Result: worldtradebook.com is not infected or malware details are not published yet.