Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=i.wik.im
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://i.wik.im/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: i.wik.im
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Keep-Alive
Date: Sun, 27 Jul 2014 02:25:27 GMT
Pragma: no-cache
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html; Charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Keep-Alive: timeout=15, max=99
Set-Cookie: PHPSESSID=0k9v2ptibik01285pa2ehll7l6; path=/; domain=.wikitree.co.kr
Set-Cookie: session_id=0k9v2ptibik01285pa2ehll7l6; path=/; domain=.wikitree.co.kr
X-Died: timeout at scan.pm line 1546.
X-Powered-By: PHP/5.3.13
GET / HTTP/1.1
Host: i.wik.im
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Keep-Alive
Date: Sun, 27 Jul 2014 02:25:27 GMT
Pragma: no-cache
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html; Charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Keep-Alive: timeout=15, max=99
Set-Cookie: PHPSESSID=0k9v2ptibik01285pa2ehll7l6; path=/; domain=.wikitree.co.kr
Set-Cookie: session_id=0k9v2ptibik01285pa2ehll7l6; path=/; domain=.wikitree.co.kr
X-Died: timeout at scan.pm line 1546.
X-Powered-By: PHP/5.3.13
Second query (visit from search engine):
GET / HTTP/1.1
Host: i.wik.im
Referer: http://www.google.com/search?q=i.wik.im
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: i.wik.im
Referer: http://www.google.com/search?q=i.wik.im
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://i.wik.im/ | 200 OK Content-Length: 125014 Content-Type: text/html | clean |
http://www.wikitree.co.kr/_js/common.js?14071817 | 200 OK Content-Length: 4963 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/view.js?14071817 | 200 OK Content-Length: 2172 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/ajax.js?14071817 | 200 OK Content-Length: 2058 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/wnow.js?14071817 | 200 OK Content-Length: 4273 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/jquery-1.7.1.min.js?14071817 | 200 OK Content-Length: 93871 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/wlayer.js?14071817 | 200 OK Content-Length: 2856 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/mover.js?14071817 | 200 OK Content-Length: 2648 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/people_in_sns.js?14071817 | 200 OK Content-Length: 619 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/main.js?14071817 | 200 OK Content-Length: 6816 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/dom.js?14071817 | 200 OK Content-Length: 1272 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/slideshow.js?14071817 | 200 OK Content-Length: 6379 Content-Type: application/x-javascript | clean |
http://www.wikitree.co.kr/_js/dhold.js?14071817 | 200 OK Content-Length: 1565 Content-Type: application/x-javascript | clean |
http://i.wik.im/rss/rss_headline.php | 200 OK Content-Length: 44752 Content-Type: text/xml | clean |
http://i.wik.im/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Keep-Alive Date: Sun, 27 Jul 2014 02:25:57 GMT Pragma: no-cache Location: http://www.wikitree.co.kr/main/news_view.php?id=test404page.js Server: Apache/2.2.3 (CentOS) Content-Length: 1394 Content-Type: text/html; Charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Keep-Alive: timeout=15, max=80 Set-Cookie: PHPSESSID=tchqsaf7vqtdl9b173h636r1v4; path=/; domain=.wikitree.co.kr Set-Cookie: session_id=tchqsaf7vqtdl9b173h636r1v4; path=/; domain=.wikitree.co.kr X-Powered-By: PHP/5.3.13 | clean |
http://www.wikitree.co.kr/main/news_view.php?id=test404page.js | 200 OK Content-Length: 97 Content-Type: text/html | clean |