Website Check

Check Your Websites for Malicious or Suspicious code.


Website Check v0.8

Check Depth : 0 1 ( Image link)

Accept Language: KO US DE CN JP IT

User-Agent : MSIE Android iPhone Chrome Safari

Private : (Detection results of private)

Save Source :

Report

*Date : 2014.11.07 10:15
*Site : http://joytalk.co.kr/
*Info : 211.115.88.98, KR(, Korea, Republic of)
*Check url : 236 counts
*Loading time : 0sec
*Google SafeBrowsing : Not founds.
*Result
 (1) user information check - 35건 발견
 (2) Suspicious url(NULL) - 19건 발견
 (3) user cookie check - 18건 발견
 (4) Suspicious script has been detected (document.write(unescape(?))) - 3건 발견
 (5) user tracking code (google-analytics.com) - 2건 발견
 (6) Suspicious script has been detected (Obfuscation URL) - 2건 발견
 (7) http://post.mm.co.kr/log/w/icon.gif - 1건 발견
 (8) 악의적으로 사용된 사례 스크립트(eval/fromCharCode) 발견 - 1건 발견
 (9) user information check - 1건 발견


http://zerocert.org/?code=5bacb2b4355c74d5020a7c9ceceed3eb62603fef06e906db2fda08a762f61db7

*Latest detected Domain
  • 이 사이트는 최근 90일 동안 악성URL 삽입된 적이 없습니다.
  • 이 사이트는 최근 90일 동안 악성코드 중개 역할한 적이 없습니다.
  • 이 사이트는 최근 90일 동안 악성코드를 유포한 적이 없습니다.
  • Relation domain not found
  • same Domain not found

http://joytalk.co.kr/
  [location] https://play.google.com/store/apps/details?id=com.anijcorp.joytalk -> pass
  [location] http://nstore.naver.com/appstore/web/detail.nhn?productNo=1109587
    [script] http://nstore.naver.com/js/splog_m.js
      [script(*)] http:?v=  -> Offline?
    [script] http://static.gn.naver.net/template/gnb_utf8.nhn?2014110710
      -> user information check
      [img] http://static.gn.naver.net/template/  -> Offline
      [script] http://static.naver.net/common/gnb/2014/sp_gnb_v5.png
      [script] http://static.naver.net/common/gnb/2014/bg_svclyr2_v2.png
      [script] http://img.naver.net/static/www/2014/loading.gif
      [script] http://static.naver.net/common/gnb/2014/bg_svclyr1_v2.png
    [script] http://nstore.naver.com/static/js/nstore/decorators/storeCommonScript-1408001579000-783628.js
      -> user information check
      -> user cookie check
      [script(*)] http:;  -> Offline?
      [script] http://static.naver.net/common/comment/btn_registry.gif
      [script] http://static.naver.net/nstore/btn_registry2_app.gif
      [script] http://static.naver.net/m/nstore/thumb/no/  -> Offline
      [script] http://static.naver.net/m/nstore/op/thumb/19/  -> Offline
      [script] http://webmsg.naver.com/api/send_url.php?NHN_CODE=
        [script] http://webmsg.naver.com/api/send_url.php?NHN_CODE=&type=login
      [script] http://static.naver.net/common/comment/btn_registry_down.gif
      [script] http://static.naver.net/nstore/btn_registry2_over_app.gif
      [script] http://sstatic.naver.net/search/images11/btn_atcmp_up_on.gif
      [script] http://static.naver.net/nstore/btn_atcmp_down_on2.gif
      [script] http://sstatic.naver.net/search/images11/btn_atcmp_down_off2.gif
    [script] http://nstore.naver.com/static/js/web/nstore/apps/detail/naverapp/detailScripts-1412230957000-234180.js
      [frame] http://nstore.naver.com/static/js/web/nstore/apps/detail/naverapp/{=personacon}  -> Offline
      [img] http://nstore.naver.com/static/js/web/nstore/apps/detail/naverapp/  -> Offline
      [script] http://nid.naver.com/new_me2day/new_me2day.nhn?ret_url=
    [script] http://nstore.naver.com/js/lib/raphael-2.1.1.min.js
      -> user information check
      [script] http://raphaeljs.com
        -> user tracking code (google-analytics.com)
        [script] http://raphaeljs.com/raphael.js
        [script] http://raphaeljs.com/site.js
      [script] http://sencha.com
        [Location] http://www.sencha.com/
      [script] http://raphaeljs.com/license.html
      [script] http://www.w3.org/TR/SVG11/feature#BasicStructure -> pass
      [script] http://www.w3.org/2000/svg -> pass
    [script] http://nstore.naver.com/js/lib/nchart-1.1.0.min.js
    [script] http://nstore.naver.com/js/lib/nhn.nstoreBarChart.merge.min.js
    [script] http://nstore.naver.com/js/lib/nhn.nstorePieChart.merge.min.js
    [img] http://nstore.naver.com/appstore/web/%22http%3A%2F%2Fme2.do%2FFVwmrYAk%22  -> Offline
    [form] http://nstore.naver.com/search/search.nhn
    [script] http://sp.naver.com/sp
      -> Suspicious url(NULL)
    [script] http://ac.nstore.naver.com/ac
      -> Suspicious url(NULL)
    [script] http://spi.naver.net/js/release/socialplugin_v1.js?
      -> user information check
      [img] http://bookmarkimgs.naver.com/img/  -> Offline
      [script] http://gn.naver.com/getLoginStatusLv2.nhn
      [script] http://me2do.naver.com/common/requestJsonp.nhn
      [script] http://relation.commcast.naver.com  -> Offline
      [script] http://bookmark.naver.com/api/exist_v2.nhn
      [script] http://bookmark.naver.com/apiSave.nhn
      [script] http://bookmark.naver.com/apiDelete.nhn
      [script] http://mail.naver.com/write/tmpl
        -> Suspicious url(NULL)
        [Location] http://nid.naver.com/nidlogin.login?mode=form&template=plogin&url=http%3A%2F%2Fmail.naver.com%2Fwrite%2Ftmpl
          -> user information check
          [script] https://nid.naver.com/login/js/common.all.js
            -> user information check
            -> user cookie check
            [script(*)] http:/m?
          [script] https://nid.naver.com/login/js/common.util.js
            -> user information check
          [form] https://nid.naver.com/nidlogin.login
            -> user information check
      [script] http://cafe.naver.com/CafeScrapView.nhn
        [script] http://cafe.naver.com/javascript/cafe_common.js?1406027759000
          -> user information check
        [script] http://cafe.naver.com/javascript/lcslog.js?1311297509000
          -> user information check
      [script] http://blog.naver.com/ScrapForm.nhn  -> Offline
      [script] http://plugin.me2day.net/v1/me2post/create_post_form.nhn  -> Offline
      [script] http://yozm.daum.net/api/popup/prePost
        -> Suspicious url(NULL)
      [script] http://memo.naver.com/plugin/view.nhn
      [script] http://webmsg.naver.com/api/send_url.php
        [script] http://webmsg.naver.com/api/send_url.php&type=login
          [Location] http://www.naver.com/testpage  -> Offline
      [script] http://www.band.us/plugin/share
        -> Suspicious url(NULL)
        [Location] https://auth.band.us/login_page?display=popup&next_url=http%3A%2F%2Fwww.band.us%2Fplugin%2Fshare
          [script] https://ssl.pstatic.net/cmstatic/auth/js/122392/all.js
            -> user information check
          [form] https://auth.band.us/v1/login_web_by_phone
      [script] http://social.naver.com/v/click  -> Offline?
      [script] http://social.naver.com/v/finish  -> Offline?
      [script] http://spi.naver.net/css/20140331/spi_standard_20140331.css
        [script] http://static.naver.net/common/spi/sp_social_plugin29.png
        [script] http://static.naver.net/common/spi/sp_social_plugin26.png
    [script] http://me2.do/FVwmrYAk
      -> Suspicious url(NULL)
      [Location] http://m.nstore.naver.com/appstore/web/detail.nhn?productNo=1109587
        [script] http://m.nstore.naver.com/js/splog_m.js
        [script] http://m.nstore.naver.com/static/js/nstore/decorators/appstoreWebScript-1415094242000-1963383.js
          -> user information check
          -> user cookie check
          [script(*)] http:&  -> Offline?
          [frame] http://m.nstore.naver.com/static/js/nstore/decorators/b;this._installApp(d,a);document.body.appendChild(c);setTimeout(function(){document.body.removeChild(c);},2000);},_installApp:function(c,b){var  -> Offline
          [frame] http://m.nstore.naver.com/static/js/nstore/decorators/b;this._callInstallMethod(a);document.body.appendChild(c);setTimeout(function(){document.body.removeChild(c);},2000);},_callInstallMethod:function(b){var  -> Offline
          [script] http://jindo.nhncorp.com/docs/jindo/archive/Jindo2-2.9.0/mobile/ko/classes/  -> Offline?
        [script] http://m.nstore.naver.com/static/js/nstore/apps/detail/naverapp/detailMainScript-1414743616000-578557.js
          -> user information check
          -> user cookie check
          [frame] http://m.nstore.naver.com/static/js/nstore/apps/detail/naverapp/b;document.body.appendChild(c);setTimeout(function(){document.body.removeChild(c);},1500);},_installApp:function(c,b){var  -> Offline
          [script] http://MobileCommentJindo.nhncorp.com/docs/MobileCommentJindo/archive/Jindo2-2.8.0/mobile/ko/classes/  -> Offline?
          [script] http://nid.naver.com/oauth/idLink.nhn?
        [img] http://m.nstore.naver.com/appstore/web/{=noImage}  -> Offline
        [form] http://m.nstore.naver.com/appstore/s2/web/search/appSearch.nhn  -> Offline
        [form] http://m.search.naver.com/search.naver
          [form] http://m.search.naver.com/?
            [script] http://m.naver.com/
          [script] http://m.search.naver.com/acao/css/2014/w_1023.css
          [script] http://m.search.naver.com/acao/css/2014/e_0918.css
          [script] http://m.search.naver.com/acao/js/2014/nx_1016.js
            -> user information check
            -> user cookie check
            [frame] http://m.search.naver.com/acao/js/2014/c}else
          [script] http://mac.search.naver.net/mobile/ac
            -> Suspicious url(NULL)
          [script] http://m.help.naver.com/faq/detail.nhn?faqId=22006
            -> Suspicious url(NULL)
            [Location] http://m.help.naver.com/serviceMain.nhn?readType=1&faqId=22006&falias=mo_serch_web&type=faqDetail
          [script] http://cr.naver.com/
          [script] http://sstatic.naver.net/au/s/mobile/_search/extensionSearch/nhn.extensionSearch_140828.js
          [script] http://sstatic.map.naver.net/widget/scripts/nlocation-widget-1.2.2.js
            -> 악의적으로 사용된 사례 스크립트(eval/fromCharCode) 발견
            -> user information check
            -> user cookie check
        [script] http://m.androidapp.naver.com/appstoreapp-last
          -> Suspicious url(NULL)
          [Location] http://m.naver.com/err/notfound.html
            [script] http://static.naver.net/www/m/im2/bu_error.gif
        [script] http://spi.naver.net/js/release/socialplugin_m_v1.js?
          -> user information check
          -> user cookie check
          [script] http://m.relation.commcast.naver.com/m  -> Offline
          [script] http://m.mail.naver.com/write/index.nhn
            [script] http://m.mail.naver.com/m/write
          [script] http://m.cafe.naver.com/CafeScrapView.nhn
          [script] http://m.blog.naver.com/OpenScrapForm.nhn
            -> Suspicious url(NULL)
            [Location] http://m.blog.naver.com/MobileErrorView.nhn;jsessionid=FE99C5B706A80CF74455972C4F687FDA.jvm1?errorType=displayMessage&msg=&pushNavigation=false
          [script] http://m.yozm.daum.net/user/message/post
            -> Suspicious url(NULL)
          [script] http://line.naver.jp/msg/text/
            [Location] http://line.naver.jp/ko
          [script] http://m.memo.naver.com/plugin/view.nhn
          [script] http://api.spi.naver.com/rating/  -> Offline
          [script] http://naverapp.naver.com/install.nhn
          [script] http://spi.naver.net/css/20140710/spi_standard_m_20140710.css
            [script] http://static.naver.net/common/spi/mb_spi_v13.png
            [script] http://static.naver.net/common/spi/mb_spi_small_v4.png
            [script] http://static.naver.net/m/me2day/s2p/s2p_lod2.gif
            [script] http://static.naver.net/m/me2day/s2p/bg_spi_h_v2.png
            [script] http://static.naver.net/common/spi/bg_spi3_h.png
            [script] http://static.naver.net/m/me2day/s2p/ld.gif
            [script] http://static.naver.net/common/spi/mb_card_v6.png
            [script] http://static.naver.net/common/spi/mb_spi_h_v13.png
            [script] http://static.naver.net/m/me2day/s2p/s2p_lod3.gif
            [script] http://static.naver.net/m/me2day/s2p/ld_h.gif
            [script] http://static.naver.net/common/spi/mb_spi_small_h_v4.png
            [script] http://static.naver.net/common/spi/mb_card_h_v6.png
          [script] http://m.bookmark.naver.com
          [script] http://itunes.apple.com/kr/app/line/id443904275?ls=1&mt=8
            -> Suspicious url(NULL)
            [Location] https://itunes.apple.com/kr/app/line/id443904275?ls=1&mt=8
          [script] http://itunes.apple.com/app/id362057947
            -> Suspicious url(NULL)
            [Location] https://itunes.apple.com/app/id362057947
          [script] http://itunes.apple.com/app/id486244601
            -> Suspicious url(NULL)
            [Location] https://itunes.apple.com/app/id486244601
          [script] http://itunes.apple.com/kr/app/id542613198
            -> Suspicious url(NULL)
            [Location] https://itunes.apple.com/kr/app/id542613198
          [script] http://nid.naver.com/nidlogin.login?svctype=262144&url=
            -> user information check
  [location] http://www.joyhunting.com/help/newhelp_notice_list.asp?n_division=17
    -> user information check
    [script] http://www.joyhunting.com/include/js/com_fnc.js?jsvid=20120203
      -> user information check
      -> user cookie check
      [script] http://www.joyhunting.com/item_mall/new_item_buy.asp?i_id=
        -> user information check
        [script] http://www.joyhunting.com/include/js/com_msg.js
        [form] http://www.joyhunting.com/item_mall/new_item_buy_ok.asp
      [script] http://www.joyhunting.com/include/event/preview5.asp
      [script] http://www.joyhunting.com/item_mall/main_shop/skin_view_pop.asp?s_id=
        [Location] http://www.joyhunting.com/item_mall/main_shop/include/member/JH_join_step1.asp?redir=/item_mall/main_shop/skin_view_pop.asp?s_id=
          -> user information check
          [script] http://wcs.naver.net/wcslog.js
            -> user cookie check
          [img] http://www.joyhunting.com/item_mall/main_shop/include/member/
            -> user information check
      [script] http://www.joyhunting.com/item_mall/new_avata_buy.asp?item_id=
        -> user information check
        [frame] http://www.joyhunting.com/item_mall/ifr_view_list.asp?my_avata=
          [Location] http://www.joyhunting.com/item_mall/include/member/JH_join_step1.asp?redir=/item_mall/ifr_view_list.asp?my_avata=
            -> user information check
            [img] http://www.joyhunting.com/item_mall/include/member/
        [script] http://www.joyhunting.com/include/js/com_cookie.js
          -> user cookie check
        [script] http://www.joyhunting.com/include/js/buy_global_avata.js
        [script] http://www.joyhunting.com/include/js/global_avata_list.js
          [script] http://www.joyhunting.com/avata_new/pop_wish.asp?reload=1
            -> user information check
            [frame] http://www.joyhunting.com/avata_new/wish.asp
    [script] http://www.joyhunting.com/include/js/com_profile.js
      -> user information check
    [script] http://www.joyhunting.com/webchat/common/mserver.js
      [Location] http://www.yasale.com/bn/m.js
        -> Suspicious script has been detected (Obfuscation URL)
        -> Suspicious script has been detected (document.write(unescape(?)))
        -> user cookie check
        [unescape] http://post.mm.co.kr/log/w/icon.gif -> Malware url  -> Offline
    [script] http://www.joyhunting.com/include/js/jquery.min.js
    [script] http://www.joyhunting.com/include/js/flashWrite.js
    [form] http://www.joyhunting.com/help/newhelp_notice_list.asp
      -> user information check
    [form] http://www.joyhunting.com/include/member/login_proc.asp
      [script] http://www.joyhunting.com/include/js/jquery-1.3.2.js
        -> user information check
      [script] http://www.joyhunting.com/include/js/jquery-ui-1.7.1.js
        [script] http://jqueryui.com/about
          -> Suspicious url(NULL)
          [Location] http://jqueryui.com/about/
            -> Suspicious script has been detected (document.write(unescape(?)))
            -> user tracking code (google-analytics.com)
            [script(*)] http://www.google-analytics.com/ga.js
            [script] http://jqueryui.com/jquery-wp-content/themes/jquery/js/jquery-1.9.1.min.js
            [script] http://jqueryui.com/jquery-wp-content/themes/jquery/js/modernizr.custom.2.6.2.min.js
            [script] http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js
            [script] http://jqueryui.com/jquery-wp-content/themes/jquery/js/plugins.js
            [script] http://jqueryui.com/jquery-wp-content/themes/jquery/js/main.js
            [script] http://use.typekit.net/wde1aof.js
            [script] http://jqueryui.com/wp-includes/js/comment-reply.min.js?ver=4.0
            [form] http://jqueryui.com/
            [form] http://jqueryui.com//jqueryui.com/
      [script] http://www.joyhunting.com/include/js/com_fnc.js
        -> user information check
        -> user cookie check
    [script] http://event.bonus365.co.kr/aia_cm/2013_02th/YE2011112301_shinsegae_7/jsp/main.jsp?site_code=121010
      -> Suspicious url(NULL)
      [Location] http://event.bonus365.co.kr/end.jsp?site_code=121010
    [script] http://www.flower112.com
      [frame] http://www.flower112.com/skin/A02/main.php?soris=
        [swf] http://www.flower112.com/skin/A02/../../skin/A02/image/flash/a02_01.swf -> pass
        [script] http://www.flower112.com/skin/A02/../../admin/inc/js/common.js
          -> user information check
          -> user cookie check
          [script] http://www.hanflower.com
            -> Suspicious url(NULL)
            [Location] http://hanflower.com
        [script] http://www.flower112.com/skin/A02/../../admin/inc/js/formcheck.js
    [script] http://images.joyhunting.com/images3/id_00.gif
    [script] http://images.joyhunting.com/images3/pw_00.gif
  [location] http://www.joyhunting.com/
    [Location] http://www.joyhunting.com/JH_main2.asp
      -> user information check
      -> user cookie check
      [swf] http://images.joyhunting.com/images3/2011_landing/swf/322_393_joy3.swf -> pass
      [swf] http://images.joyhunting.com/images3/main_renewal/swf/map.swf -> pass
      [swf] http://images.joyhunting.com/images3/main_renewal/swf/thema.swf -> pass
      [swf] http://images.joyhunting.com/images3/main_renewal/swf/slide.swf -> pass
      [swf] http://images.joyhunting.com/images3/main_renewal/swf/search.swf -> pass
      [swf] http://images.joyhunting.com/images3/main_renewal/swf/chat_new.swf -> pass
      [swf] http://www.joyhunting.com/.swf -> pass
      [frame] http://www.joyhunting.com/include/asp/ifr_todaymeeting_new.asp
      [frame] http://www.joyhunting.com/include/asp/ifr_newmem_new.asp
      [frame] http://www.joyhunting.com/include/asp/ifr_item.asp
        [script] http://www.joyhunting.com/include/js/JH_global_fnc.js
          -> user information check
          -> user cookie check
      [script] http://www.joyhunting.com/include/js/new_pop.js
      [script] http://www.joyhunting.com/include/js/JH_global_fnc.js?jsvid=20120203
        -> user information check
        -> user cookie check
      [script] http://www.joyhunting.com/include/js/load_flash.js
        [Location] http://lotte.golfcube.co.kr/conf/s/flash.js
          -> Suspicious script has been detected (Obfuscation URL)
          -> Suspicious script has been detected (document.write(unescape(?)))
          -> user information check
          -> user cookie check
      [script] http://www.joyhunting.com/include/js/new_main.js
        -> user cookie check
      [img] http://ad.yieldmanager.com/pixel?id=1969372&t=2
        -> Suspicious url(NULL)
        [Location] http://ads.yahoo.com/pixel?id=1969372&t=2&_msd=1&rmxbkn=0&_hnam=ad.yieldmanager.com&_cbv=2867930429
      [form] http://www.joyhunting.com/re_main/JH_member_Search1.asp  -> Offline
      [form] http://www.joyhunting.com/opencafe/cafe_new_search.asp
        [Location] http://www.joyhunting.com/opencafe/include/member/JH_join_step1.asp?redir=/opencafe/cafe_new_search.asp
          -> user information check
          [img] http://www.joyhunting.com/opencafe/include/member/
            -> user information check
      [script] http://hanatvevent.co.kr/event/joy_event.html  -> Offline?
      [script] http://www.ilikeclick.com/track/click.php?dts_code=100897890020065319000036198000000000000&DTS_UID=
      [script] http://event.cocas.co.kr/reward/reward_in.asp?eventcd=12&mediacd=2&rewardkey=
      [script] http://event.cocas.co.kr/reward/reward_in.asp?eventcd=12&mediacd=4&rewardkey=
      [script] http://www.joyhunting.com/con_help/con_help_1.html
        [frame] http://www.joyhunting.com/con_help/menu1_1.html
      [script] http://images.joyhunting.com/images3/main_renewal/swf/  -> Offline
  [script] http://www.joyhunting.com/help/qna/concern_qna.asp
    [script] http://www.joyhunting.com/include/js/com_fileupload.js
      [script] http://upload.joyhunting.com/anij/upload.asp?fname=
        [form] http://upload.joyhunting.com/anij/upload_ok.asp  -> Offline
      [script] http://upload.joyhunting.com/upload1/upload_file.asp?fname=  -> Offline
      [script] http://upload.joyhunting.com/upload1/upload.asp?fname=  -> Offline
      [script] http://upload.joyhunting.com/upload1/upload_qna.asp?fname=  -> Offline
    [form] http://www.joyhunting.com/help/qna/concern_qna_proc.asp
  [script] http://www.joyhunting.com/help/qna/ad_qna.asp
    [form] http://www.joyhunting.com/help/qna/ad_qna_proc.asp
*Country
unknown



*Whois
query : joytalk.co.kr


# KOREAN(UTF8)

도메인이름 : joytalk.co.kr
등록인 : 홍승용
책임자 : 홍승용
책임자 전자우편 : h444375@naver.com
등록일 : 2012. 09. 13.
최근 정보 변경일 : 2019. 09. 02.
사용 종료일 : 2026. 09. 13.
정보공개여부 : N
등록대행자 : 호스트센터(주)(http://www.domainclub.kr)
DNSSEC : 미서명

1차 네임서버 정보
호스트이름 : ns1.joytalk.co.kr
IP 주소 : 211.115.88.122

2차 네임서버 정보
호스트이름 : ns2.joytalk.co.kr
IP 주소 : 211.115.88.122

네임서버 이름이 .kr이 아닌 경우는 IP주소가 보이지 않습니다.


# ENGLISH

Domain Name : joytalk.co.kr
Registrant : Hong
Administrative Contact(AC) : Hong
AC E-Mail : h444375@naver.com
Registered Date : 2012. 09. 13.
Last Updated Date : 2019. 09. 02.
Expiration Date : 2026. 09. 13.
Publishes : N
Authorized Agency : hostcenter(http://www.domainclub.kr)
DNSSEC : unsigned

Primary Name Server
Host Name : ns1.joytalk.co.kr
IP Address : 211.115.88.122

Secondary Name Server
Host Name : ns2.joytalk.co.kr
IP Address : 211.115.88.122


- KISA/KRNIC WHOIS Service -


*Reference
 VIRUSTOTAL : domain | ip | hash url | hash file
 Google SafeBrowsing(GSB) :
 URLVoid : domain
 Malware Domain List : domain
 SCUMWARE : domain | ip
 Project Honey Pot : ip
 Ransomware Tracker : domain
 Threat Crowd : domain | ip | hash file
 ZeroCERT Safeguard : domain | ip

*etc
  Stopbadware | Norton Safe | McAfee siteadvisor | Phish tank | Tcpiputils

[Info] Changing api service domain address (center.zerocert.org -> cert.zero.camp), API Reference