Scanned pages/files
Request | Server response | Status |
http://youthmentalhealthhalton.ca/ | 200 OK Content-Length: 8527 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 0x0 src: http://www.youtube.com/embed/1odtwnodk4a?rel=0&autoplay=1&loop=1&playlist=1odtwnodk4a <iframe width="0" height="0" src="http://www.youtube.com/embed/1odtwnodk4a?rel=0&autoplay=1&loop=1&playlist=1odtwnodk4a" frameborder="0" allowfullscreen="" __idm_id__="282625"> Deface/Content modification. The following signature was found: .::Hacked By::. ...[4781 bytes skipped]... or:black;font-size:80px;text-shadow: 0 0 3px red, 0px 0px 20px red">"</span></span></b></h1> <a href="https://www.facebook.com/807058752718174" target="_blank"> <img src="http://oi62.tinypic.com/vifocj.jpg" title="BloodSecurity" width="20%"></a> <p> <span style="color:black;font-size:45px;text-shadow: 0 0 3px white, 0px 0px 20px white"><b>.::Hacked By::.</b></span><br> <span style="color:black;font-size:40px;text-shadow: 0 0 3px red, 0px 0px 20px red"><b> Bl4ckb133d </b></span><br><br> <span style="font-size:20px;text-shadow:red 0px 0px 3px">Your Site's Security Has Been Compromised By <span style="font-size:20px;font-family:Iceberg;color:red;text-shadow:#000 0px 0px 3px">#BloodSecurity</span><br> <span style="font-size:20p ...[4918 bytes skipped]... | ||
http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js | 200 OK Content-Length: 92629 Content-Type: text/javascript | clean |
http://goo.gl/jeD8fN | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, no-store, max-age=0, must-revalidate Connection: close Date: Tue, 08 Dec 2015 15:08:35 GMT Pragma: no-cache Accept-Ranges: none Location: http://kurkino.net.ru/block/BSH.js Server: GSE Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Fri, 01 Jan 1990 00:00:00 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block | clean |
http://kurkino.net.ru/block/bsh.js | 404 Not Found Content-Length: 570 Content-Type: text/html | clean |
http://kurkino.net.ru/test404page.js | 404 Not Found Content-Length: 570 Content-Type: text/html | clean |
http://youthmentalhealthhalton.ca/chrome-extension://hhojmcideegachlhfgfdhailpfhgknjm/web_accessible_resources/index.js | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/javascript | clean |
http://suspended.hostgator.com/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: text/javascript | clean |
http://youthmentalhealthhalton.ca/chrome-extension://hhojmcideegachlhfgfdhailpfhgknjm/web_accessible_resources/ | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: youthmentalhealthhalton.ca
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Dec 2015 15:08:34 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 8527
Content-Type: text/html
Last-Modified: Sun, 02 Aug 2015 06:05:08 GMT
...8527 bytes of data.
GET / HTTP/1.1
Host: youthmentalhealthhalton.ca
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Dec 2015 15:08:34 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 8527
Content-Type: text/html
Last-Modified: Sun, 02 Aug 2015 06:05:08 GMT
...8527 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: youthmentalhealthhalton.ca
Referer: http://www.google.com/search?q=youthmentalhealthhalton.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: youthmentalhealthhalton.ca
Referer: http://www.google.com/search?q=youthmentalhealthhalton.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=youthmentalhealthhalton.ca
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://youthmentalhealthhalton.ca/
Result: youthmentalhealthhalton.ca is not infected or malware details are not published yet.
Result: youthmentalhealthhalton.ca is not infected or malware details are not published yet.