Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=etira.co.kr
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.etira.co.kr/ | HTTP/1.1 302 Object moved Cache-Control: private Date: Sun, 21 Dec 2014 10:51:43 GMT Location: http://www.etira.co.kr/main Server: Microsoft-IIS/6.0 Content-Length: 148 Content-Type: text/html P3P: CP=ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC Set-Cookie: PUID=77C3B8B362B44FC0A53CA9CD1C56F4CA; domain=etira.co.kr; path=/ Set-Cookie: ASPSESSIONIDACTQCQQS=JHJPFEEDMGDAOHCMLHBINDIO; path=/ | clean |
http://www.etira.co.kr/main | HTTP/1.1 301 Moved Permanently Date: Sun, 21 Dec 2014 10:51:43 GMT Location: http://www.etira.co.kr/main/ Server: Microsoft-IIS/6.0 Content-Length: 174 Content-Type: text/html | clean |
http://www.etira.co.kr/main/ | HTTP/1.1 302 Object moved Cache-Control: private Date: Sun, 21 Dec 2014 10:51:44 GMT Location: /main/main_real.asp Server: Microsoft-IIS/6.0 Content-Length: 140 Content-Type: text/html P3P: CP=ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC Set-Cookie: PUID=4DCB26A57746423FA571ACCB6E703F94; domain=etira.co.kr; path=/ Set-Cookie: ASPSESSIONIDACTQCQQS=KHJPFEEDOJFBEKEJIHEIIEFE; path=/ | clean |
http://www.etira.co.kr/main/main_real.asp | 200 OK Content-Length: 6751 Content-Type: text/html | clean |
http://www.etira.co.kr/jscript/common.js | 200 OK Content-Length: 22339 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) String.prototype.trim = function() {
return this.replace(/(^\s*)|(\s*$)/g, ""); } String.prototype.stripspace = function() { return this.replace(/ /g, ""); } String.prototype.replaceAll = function(a, b) { var s = this; var n1, n2, s1, s2; while (true) { if ( s=="" || a=="" ) break; n1 = s.indexOf(a); if ( n1 < 0 ) break; n2 = n1 + a.length; if ( n1==0 ) { s1 = b; } e Antivirus reports:
| ||
http://www.etira.co.kr/jscript/embed.js | 200 OK Content-Length: 2951 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/ajax.js | 200 OK Content-Length: 2356 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/json.js | 200 OK Content-Length: 5093 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/rollover.js | 200 OK Content-Length: 1033 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/user_func.js | 200 OK Content-Length: 2552 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/default.asp | HTTP/1.1 302 Object moved Cache-Control: private Date: Sun, 21 Dec 2014 10:51:56 GMT Location: http://www.etira.co.kr/main Server: Microsoft-IIS/6.0 Content-Length: 148 Content-Type: text/html P3P: CP=ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC Set-Cookie: PUID=E0EBEAA0E0CF43B6A190453AE36B1038; domain=etira.co.kr; path=/ Set-Cookie: ASPSESSIONIDACTQCQQS=OHJPFEEDLBDALCAMAPMOKKMK; path=/ | clean |
http://www.etira.co.kr/test404page.js | 404 Not Found Content-Length: 1466 Content-Type: text/html | clean |
http://www.etira.co.kr/page.asp?uid=13 | 200 OK Content-Length: 17689 Content-Type: text/html | clean |
http://www.etira.co.kr/jscript/cookie.js | 200 OK Content-Length: 1022 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/floating.js | 200 OK Content-Length: 3497 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/jscript/left_floating.js | 200 OK Content-Length: 3583 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/goods/content.asp?guid=817 | 200 OK Content-Length: 121154 Content-Type: text/html | clean |
http://www.etira.co.kr/sns/scrap.js | 200 OK Content-Length: 831 Content-Type: application/x-javascript | clean |
http://www.etira.co.kr/board/list.asp?board=etira_after | 200 OK Content-Length: 32736 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: etira.co.kr
Result:
GET / HTTP/1.1
Host: etira.co.kr
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: etira.co.kr
Referer: http://www.google.com/search?q=etira.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: etira.co.kr
Referer: http://www.google.com/search?q=etira.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.