Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=netizenmall.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: neprosto.ucoz.ru
Result:
HTTP/1.1 500 Server Error
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Tue, 16 Dec 2014 13:23:13 GMT
Pragma: no-cache
Server: uServ/3.2.2
Content-Type: text/html; charset=UTF-8
Set-Cookie: 0neprostouCoz=; path=/; expires=Sun, 16-Dec-2012 13:23:13 GMT; domain=.neprosto.ucoz.ru;
GET / HTTP/1.1
Host: neprosto.ucoz.ru
Result:
HTTP/1.1 500 Server Error
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Tue, 16 Dec 2014 13:23:13 GMT
Pragma: no-cache
Server: uServ/3.2.2
Content-Type: text/html; charset=UTF-8
Set-Cookie: 0neprostouCoz=; path=/; expires=Sun, 16-Dec-2012 13:23:13 GMT; domain=.neprosto.ucoz.ru;
Second query (visit from search engine):
GET / HTTP/1.1
Host: neprosto.ucoz.ru
Referer: http://www.google.com/search?q=neprosto.ucoz.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: neprosto.ucoz.ru
Referer: http://www.google.com/search?q=neprosto.ucoz.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://netizenmall.com/ | HTTP/1.1 200 OK Connection: close Date: Wed, 04 Jun 2014 16:37:04 GMT Server: Apache Content-Length: 256 Content-Type: text/html Set-Cookie: domain=deleted; expires=Tue, 04 Jun 2013 16:37:03 GMT; path=/; domain=gabia.com X-Powered-By: PHP/4.4.9 | malicious |
http://www.netizennews.com/ | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 04 Jun 2014 16:37:07 GMT Pragma: no-cache Location: /main/index.html Server: Apache/2.2.3 (CentOS) Content-Length: 0 Content-Type: text/html; charset=euc-kr Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=261jkv6fglft4m0iun7j6olpm7; path=/ Set-Cookie: rbUser=MTQwMTg5OTgyNzM2MDQ%3D; expires=Thu, 05-Jun-2014 16:37:07 GMT; path=/ Set-Cookie: rankup_log_start=true; expires=Wed, 04-Jun-2014 17:07:07 GMT; path=/ X-Powered-By: PHP/5.1.6 | clean |
http://www.netizennews.com/main/index.html | 200 OK Content-Length: 41938 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 0x0 src: http://www.2putting.co.kr/upload/pyp/index.html <iframe src=http://www.2putting.co.kr/upload/pyp/index.html width=0 height=0> Hidden iFrame found. size: 1x0 src: http://intra.cyts.co.kr/board/m.html <iframe src=http://intra.cyts.co.kr/board/m.html width=1 height=0> Hidden iFrame found. size: 0x0 src: http://www.nnovita.co.kr/nshop/upload/x/m.html <iframe src=http://www.nnovita.co.kr/nshop/upload/x/m.html width=0 height=0> Hidden iFrame found. size: 100x0 src: http://intra.cyts.co.kr/board/m.html <iframe src=http://intra.cyts.co.kr/board/m.html width=100 height=0> Hidden iFrame found. size: 0x0 src: http://cfoschool.co.kr/m.html <iframe src=http://cfoschool.co.kr/m.html width=0 height=0> Hidden iFrame found. size: 1x0 src: http://cfoschool.co.kr/m.html <iframe src=http://cfoschool.co.kr/m.html width=1 height=0> | ||
http://www.netizennews.com/rankup_module/rankup_board/rankup_board.js | 200 OK Content-Length: 40905 Content-Type: application/x-javascript | clean |
http://netizenmall.com/Libs/_js/rankup_tab.js | 404 Not Found Content-Length: 285 Content-Type: text/html | clean |
http://netizenmall.com/test404page.js | 404 Not Found Content-Length: 277 Content-Type: text/html | clean |
http://netizenmall.com/Libs/_js/tool2.class.js | 404 Not Found Content-Length: 286 Content-Type: text/html | clean |