Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mgcp.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 13 Jun 2014 03:20:17 GMT
Server: Microsoft-IIS/9.0
Content-Type: text/html
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
Set-Cookie: PHPSESSID=4e93886574a186072dca5f0354e3d152; path=/
GET / HTTP/1.1
Host: mgcp.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 13 Jun 2014 03:20:17 GMT
Server: Microsoft-IIS/9.0
Content-Type: text/html
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
Set-Cookie: PHPSESSID=4e93886574a186072dca5f0354e3d152; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: mgcp.kr
Referer: http://www.google.com/search?q=mgcp.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mgcp.kr
Referer: http://www.google.com/search?q=mgcp.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://mgcp.kr/ | 200 OK Content-Length: 32776 Content-Type: text/html | clean |
http://mgcp.kr/../home/introduce.php | 501 Method Not Implemented Content-Length: 413 Content-Type: text/html | clean |
http://mgcp.kr/test404page.js | HTTP/1.1 302 Found Connection: close Date: Fri, 13 Jun 2014 03:20:22 GMT Location: http://404.mireene.com/error/404.html Server: Microsoft-IIS/9.0 Content-Length: 289 Content-Type: text/html; charset=iso-8859-1 | clean |
http://404.mireene.com/error/404.html | 200 OK Content-Length: 538 Content-Type: text/html | clean |
http://404.mireene.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Fri, 13 Jun 2014 03:20:23 GMT Location: http://404.mireene.com/error/404.html Server: Microsoft-IIS/9.0 Content-Length: 297 Content-Type: text/html; charset=iso-8859-1 | clean |
http://mgcp.kr/../home/master.php | 501 Method Not Implemented Content-Length: 410 Content-Type: text/html | clean |
http://mgcp.kr/../home/summary.php | 501 Method Not Implemented Content-Length: 411 Content-Type: text/html | clean |
http://mgcp.kr/../zb4/zboard.php?id=results | 501 Method Not Implemented Content-Length: 409 Content-Type: text/html | clean |
http://mgcp.kr/../home/rocation.php | 501 Method Not Implemented Content-Length: 412 Content-Type: text/html | clean |
http://mgcp.kr/../home/product1.php | 501 Method Not Implemented Content-Length: 412 Content-Type: text/html | clean |
http://mgcp.kr/../home/product2.php | 501 Method Not Implemented Content-Length: 412 Content-Type: text/html | clean |
http://mgcp.kr/../home/product3.php | 501 Method Not Implemented Content-Length: 412 Content-Type: text/html | clean |
http://mgcp.kr/../home/product4.php | 501 Method Not Implemented Content-Length: 412 Content-Type: text/html | clean |
http://mgcp.kr/../zb4/zboard.php?id=sale | 501 Method Not Implemented Content-Length: 409 Content-Type: text/html | clean |
http://mgcp.kr/../zb4/zboard.php?id=product1 | 501 Method Not Implemented Content-Length: 409 Content-Type: text/html | clean |
http://mgcp.kr/../zb4/zboard.php?id=product2 | 501 Method Not Implemented Content-Length: 409 Content-Type: text/html | clean |
http://mgcp.kr/../zb4/zboard.php?id=product3 | 501 Method Not Implemented Content-Length: 409 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mgcp.kr
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://mgcp.kr/
Result: mgcp.kr is not infected or malware details are not published yet.
Result: mgcp.kr is not infected or malware details are not published yet.