Scanned pages/files
Request | Server response | Status |
http://xx.org.ua/ | 200 OK Content-Length: 1637 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Av3LoXiS ...[317 bytes skipped]... # # # # # # # # # # # # # # # # # # # # # # # # ## ##### ####### #### # # # ##### --> <html> <meta name="keywords" content="Av3LoXiS"> <meta name="description" content="Av3LoXiS"> <link rel="shortcut icon" href="http://i.hizliresim.com/4YqQAJ.png" type="image/x-icon"> <title>Hacked By Av3LoXiS</title> </head><body bgcolor="#000000"> <center><img src="http://i.hizliresim.com/q98vrd.png" width="766" height="400"><br><br><br><br> <table width="100%" height="10%"> <tbody><tr><td align="center"> <span style="font: 50px tahoma;size:100px;color:red;text-shadow: 0px 0px 60px;"><strong>Hacked By Av3LoXiS</strong></span></td> < ...[870 bytes skipped]... | ||
http://xx.org.ua/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xx.org.ua
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 11 Oct 2015 19:29:24 GMT
Server: nginx
Content-Type: text/html; charset=UTF-8
GET / HTTP/1.1
Host: xx.org.ua
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 11 Oct 2015 19:29:24 GMT
Server: nginx
Content-Type: text/html; charset=UTF-8
Second query (visit from search engine):
GET / HTTP/1.1
Host: xx.org.ua
Referer: http://www.google.com/search?q=xx.org.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xx.org.ua
Referer: http://www.google.com/search?q=xx.org.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xx.org.ua
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://xx.org.ua/
Result: xx.org.ua is not infected or malware details are not published yet.
Result: xx.org.ua is not infected or malware details are not published yet.