Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=winhelp.co.kr
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: winhelp.co.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 12:25:51 GMT
Server: Apache/2.4.3 (Unix) PHP/5.3.19
Content-Length: 69
Content-Type: text/html
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
Set-Cookie: PHPSESSID=sbvr2j0pc43kcie9jrgd5qk590; path=/
Set-Cookie: f33d2ed86bd82d4c22123c9da444d8ab=MTQxMjUxMTk1MQ%3D%3D; expires=Mon, 05-Oct-2015 12:25:51 GMT; path=/
Set-Cookie: 96b28b766b7e0699aa91c9ff3d890663=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Set-Cookie: 2a0d2363701f23f8a75028924a3af643=NzguMTU4LjExLjIyNg%3D%3D; expires=Mon, 06-Oct-2014 12:25:51 GMT; path=/
X-Powered-By: PHP/5.3.19
...69 bytes of data.
GET / HTTP/1.1
Host: winhelp.co.kr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 12:25:51 GMT
Server: Apache/2.4.3 (Unix) PHP/5.3.19
Content-Length: 69
Content-Type: text/html
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
Set-Cookie: PHPSESSID=sbvr2j0pc43kcie9jrgd5qk590; path=/
Set-Cookie: f33d2ed86bd82d4c22123c9da444d8ab=MTQxMjUxMTk1MQ%3D%3D; expires=Mon, 05-Oct-2015 12:25:51 GMT; path=/
Set-Cookie: 96b28b766b7e0699aa91c9ff3d890663=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Set-Cookie: 2a0d2363701f23f8a75028924a3af643=NzguMTU4LjExLjIyNg%3D%3D; expires=Mon, 06-Oct-2014 12:25:51 GMT; path=/
X-Powered-By: PHP/5.3.19
...69 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: winhelp.co.kr
Referer: http://www.google.com/search?q=winhelp.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: winhelp.co.kr
Referer: http://www.google.com/search?q=winhelp.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://winhelp.co.kr/ | 200 OK Content-Length: 69 Content-Type: text/html | clean |
http://winhelp.co.kr/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sun, 05 Oct 2014 12:25:52 GMT Location: http://winclean.kr/missing.html Server: Apache/2.4.3 (Unix) PHP/5.3.19 Content-Length: 215 Content-Type: text/html; charset=iso-8859-1 | clean |
http://winclean.kr/missing.html | 500 Can't connect to winclean.kr:80 (Bad hostname) Content-Length: 154 Content-Type: text/plain | clean |
http://winclean.kr/test404page.js | 500 Can't connect to winclean.kr:80 (Bad hostname) Content-Length: 154 Content-Type: text/plain | clean |