Scanned pages/files
Request | Server response | Status |
http://zephyur.com/ | 200 OK Content-Length: 7007 Content-Type: text/html | suspicious |
Deface/Content modification. The following signature was found: Hacked By Tested404 ...[5353 bytes skipped]... r/><img src="http://s7.postimg.org/8p826xul7/8i_IL1_Cx.png" width="400" height="400"> <br> <center> <a class="shadow" href="IST Team" target="new"><font color="#FFFFFF" size="4"></font></a><br /> <a class="shadow" href="https://www.facebook.com/pages/Indonesian-Security-Tester-Team/161254764025193" target="_blank"><font color="#FF0000" size="8">Hacked By Tested404</font></a> <blink></blink><br /> <br> <font size="19" face="Tangerine" style="color: #ffffff; text-shadow: 0px 1px 7px white;">Please , Come Back soon.</font> <br> <sup></sup><br> <center> <a class="shadow" href="IST Team" target="new"><font color="#FF0000" size="7"><marquee width=65%>Special Thanks To :[+]My Family : | BroPrincesswap | Mr_Xero | TJC26 ...[1869 bytes skipped]... | ||
http://www.developer-indonesia.web.id/style/salju.js | 500 Can't connect to www.developer-indonesia.web.id:80 Content-Length: 205 Content-Type: text/plain | clean |
http://www.developer-indonesia.web.id/test404page.js | 500 Can't connect to www.developer-indonesia.web.id:80 Content-Length: 205 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: zephyur.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 22 Jul 2015 20:35:12 GMT
Server: nginx/1.8.0
Content-Type: text/html
GET / HTTP/1.1
Host: zephyur.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 22 Jul 2015 20:35:12 GMT
Server: nginx/1.8.0
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: zephyur.com
Referer: http://www.google.com/search?q=zephyur.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: zephyur.com
Referer: http://www.google.com/search?q=zephyur.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zephyur.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://zephyur.com/
Result: zephyur.com is not infected or malware details are not published yet.
Result: zephyur.com is not infected or malware details are not published yet.