Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=study.ibluerain.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: study.ibluerain.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Keep-Alive
Date: Wed, 16 Apr 2014 19:12:10 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Keep-Alive: timeout=5, max=93
P3P: CP='ALL DSP COR MON LAW OUR LEG DEL'
Set-Cookie: visited=1397675530; path=/; domain=study.ibluerain.com
X-UA-Compatible: IE=Edge
GET / HTTP/1.1
Host: study.ibluerain.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: Keep-Alive
Date: Wed, 16 Apr 2014 19:12:10 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Keep-Alive: timeout=5, max=93
P3P: CP='ALL DSP COR MON LAW OUR LEG DEL'
Set-Cookie: visited=1397675530; path=/; domain=study.ibluerain.com
X-UA-Compatible: IE=Edge
Second query (visit from search engine):
GET / HTTP/1.1
Host: study.ibluerain.com
Referer: http://www.google.com/search?q=study.ibluerain.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: study.ibluerain.com
Referer: http://www.google.com/search?q=study.ibluerain.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://study.ibluerain.com/ | 200 OK Content-Length: 122668 Content-Type: text/html | clean |
http://s1.daumcdn.net/cfs.tistory/v/120717113544/blog/plugins/lightbox/lightbox_plus_ope.js | 200 OK Content-Length: 15558 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/140206144801/blog/plugins/A_ShareEntryWithSNS/script/shareEntryWithSNS.js | 200 OK Content-Length: 893 Content-Type: application/javascript | clean |
http://durl.me/js/addDurl.js?nil_ch=tistory | 200 OK Content-Length: 705 Content-Type: text/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/0/blog/plugins/findingNemo/FN_Script.js | 200 OK Content-Length: 1356 Content-Type: application/javascript | clean |
http://cfs.tistory.com/custom/blog/0/0/FindNemoData.js | 200 OK Content-Length: 7991 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/130613153857/blog/plugins/TistoryProfileLayer/profile.js | 200 OK Content-Length: 11362 Content-Type: application/javascript | clean |
http://ajax.microsoft.com/ajax/jquery/jquery-1.4.2.min.js | 200 OK Content-Length: 72413 Content-Type: application/x-javascript | clean |
http://fx.livere.co.kr:8080/js/t_livere_lib.js?v=1.0 | 200 OK Content-Length: 6915 Content-Type: application/x-javascript | clean |
http://fx.livere.co.kr:8080/js/t_livere.js?v=1.0 | 200 OK Content-Length: 9050 Content-Type: application/x-javascript | clean |
http://fx.livere.co.kr:8080/consumers/tistory/livere_tistory.js?v=1.0 | 200 OK Content-Length: 11461 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/120919102824/blog/script/lib/jigu/jigu-latest.min.js | 200 OK Content-Length: 49917 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/130902133405/blog/script/T.js | 200 OK Content-Length: 6628 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/121017170257/blog/script/EAF2.js | 200 OK Content-Length: 16600 Content-Type: application/javascript | clean |
http://s1.daumcdn.net/cfs.tistory/v/140404091959/blog/script/common.js | 200 OK Content-Length: 56048 Content-Type: application/javascript | clean |