Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zfile.co.kr
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://zfile.co.kr/ | 200 OK Content-Length: 99765 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: image1.zfile.co.kr </table> <!--ADD_CODE--> </td> <td width="750" valign="top" align="right"> <script src="http://www.zfile.co.kr/js/storage.php" language="javascript"></script> <script type="text/javascript"> //¿äÀϺ° 10%¼¼ÀÏ À̹ÌÁö ·¹ÀÌ¾î º¸¿©ÁÖ±â function getRealOffsetLeft_1(o){ return o ? o.offsetLeft + getRealOffsetLeft_1(o.offsetParent) : 0; } function rePla ...[4473 bytes skipped]... | ||
http://www.zfile.co.kr/js/storage.php | 200 OK Content-Length: 5342 Content-Type: text/html | clean |
http://www.zfile.co.kr/test404page.js | 404 Not Found Content-Length: 342 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: zfile.co.kr
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache,must-revalidate
Connection: close
Date: Fri, 26 Dec 2014 09:06:02 GMT
Pragma: no-cache
ETag: "Thu 18 Dec 2014 12:00:49"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 PHP/4.4.7
Content-Type: text/html; charset=EUC-KR
Last-Modified: Thu 18 Dec 2014 12:00:49 GMT
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
X-Powered-By: PHP/4.4.7
GET / HTTP/1.1
Host: zfile.co.kr
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache,must-revalidate
Connection: close
Date: Fri, 26 Dec 2014 09:06:02 GMT
Pragma: no-cache
ETag: "Thu 18 Dec 2014 12:00:49"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.8e-fips-rhel5 PHP/4.4.7
Content-Type: text/html; charset=EUC-KR
Last-Modified: Thu 18 Dec 2014 12:00:49 GMT
P3P: CP="ALL CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC OTC"
X-Powered-By: PHP/4.4.7
Second query (visit from search engine):
GET / HTTP/1.1
Host: zfile.co.kr
Referer: http://www.google.com/search?q=zfile.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: zfile.co.kr
Referer: http://www.google.com/search?q=zfile.co.kr
Result:
The result is similar to the first query. There are no suspicious redirects found.