Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: discovery-korea.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Apr 2014 21:39:09 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: MayavadeeSession=a%3A4%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%228f462cbce5c25ee4184d51eb33ce5b51%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A13%3A%2278.158.11.226%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A50%3A%22Mozilla%2F4.0+%28compatible%3B+MSIE+8.0%3B+Windows+NT+5.1%29%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1396993149%3B%7D5e3bb7a8546622b7e2bdcc38e5a4dd55; expires=Tue, 08-Apr-2014 23:39:09 GMT; path=/
X-Died: timeout at scan.pm line 1538.
X-Powered-By: PleskLin
GET / HTTP/1.1
Host: discovery-korea.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Apr 2014 21:39:09 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: MayavadeeSession=a%3A4%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%228f462cbce5c25ee4184d51eb33ce5b51%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A13%3A%2278.158.11.226%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A50%3A%22Mozilla%2F4.0+%28compatible%3B+MSIE+8.0%3B+Windows+NT+5.1%29%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1396993149%3B%7D5e3bb7a8546622b7e2bdcc38e5a4dd55; expires=Tue, 08-Apr-2014 23:39:09 GMT; path=/
X-Died: timeout at scan.pm line 1538.
X-Powered-By: PleskLin
Second query (visit from search engine):
GET / HTTP/1.1
Host: discovery-korea.com
Referer: http://www.google.com/search?q=discovery-korea.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: discovery-korea.com
Referer: http://www.google.com/search?q=discovery-korea.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://discovery-korea.com/ | 200 OK Content-Length: 4940 Content-Type: text/html | clean |
http://discovery-korea.com/public/frontend/js/jquery-1.5.2.min.js | 200 OK Content-Length: 37202 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.colorbox.js | 200 OK Content-Length: 23654 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.nivo.slider.js | 200 OK Content-Length: 13607 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.tipTip.js | 200 OK Content-Length: 6871 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.slidetext.js | 200 OK Content-Length: 2761 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.popeye-2.0.4.min.js | 200 OK Content-Length: 7682 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.validate.pack.js | 200 OK Content-Length: 14367 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.start.js | 200 OK Content-Length: 108 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.flash.js | 200 OK Content-Length: 3297 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/js/jquery.sifr.js | 200 OK Content-Length: 3174 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/fancybox/jquery.mousewheel-3.0.4.pack.js | 200 OK Content-Length: 1279 Content-Type: text/javascript | clean |
http://discovery-korea.com/public/frontend/fancybox/jquery.fancybox-1.3.4.pack.js | 200 OK Content-Length: 15624 Content-Type: text/javascript | clean |
http://discovery-korea.com/test404page.js | 404 Not Found Content-Length: 1024 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=discovery-korea.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://discovery-korea.com/
Result: discovery-korea.com is not infected or malware details are not published yet.
Result: discovery-korea.com is not infected or malware details are not published yet.