$ 0 0 found the hackers code in global.asax file this is where the file redirected to: phps.aaassl.eu/api.php