New scan:

Malware Scanner report for f10-css.clan.su

Malicious/Suspicious/Total urls checked
11/0/18
11 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://f10-css.clan.su/
200 OK
Content-Length: 69120
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://s104.ucoz.net/src/jquery-1.7.2.js
200 OK
Content-Length: 94840
Content-Type: text/javascript
clean
http://s104.ucoz.net/src/ulightbox/ulightbox.js
200 OK
Content-Length: 22097
Content-Type: text/javascript
clean
http://s104.ucoz.net/src/uwnd.js?2
200 OK
Content-Length: 228554
Content-Type: text/javascript
clean
http://f10-css.clan.su/index/0-2
200 OK
Content-Length: 26084
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/load
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Connection: close
Date: Tue, 30 Jun 2015 09:48:07 GMT
Location: http://f10-css.clan.su/load/
Server: uServ/3.2.2
Content-Type: application/octet-stream
Set-Cookie: 6f10-cssuCoz=; path=/; expires=Sun, 30-Jun-2013 09:48:07 GMT; domain=.f10-css.clan.su;
clean
http://f10-css.clan.su/load/
200 OK
Content-Length: 19467
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/photo
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Connection: close
Date: Tue, 30 Jun 2015 09:48:07 GMT
Location: http://f10-css.clan.su/photo/
Server: uServ/3.2.2
Content-Type: application/octet-stream
Set-Cookie: 6f10-cssuCoz=; path=/; expires=Sun, 30-Jun-2013 09:48:08 GMT; domain=.f10-css.clan.su;
clean
http://f10-css.clan.su/photo/
200 OK
Content-Length: 19550
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/sostav_klana/0-4
200 OK
Content-Length: 25308
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/pobedy_porazhenija_cw/0-5
200 OK
Content-Length: 19188
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/forum
200 OK
Content-Length: 19479
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/sostav_klana_1_6/0-6
200 OK
Content-Length: 19378
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/navigator/0-8
200 OK
Content-Length: 74454
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/sekretnye_kody_zombie_mod/0-10
200 OK
Content-Length: 21665
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/index/3
HTTP/1.1 302 Found
Cache-Control: private
Connection: close
Date: Tue, 30 Jun 2015 09:48:13 GMT
Location: http://f10-css.clan.su/register
Server: uServ/3.2.2
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: 6f10-cssuCoz=; path=/; expires=Sun, 30-Jun-2013 09:48:13 GMT; domain=.f10-css.clan.su;
clean
http://f10-css.clan.su/register
200 OK
Content-Length: 28159
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!84!68!32!118!65!108!105!103!110!61!34!109!105!100!100!108!101!34!32!97!108!105!103!110!61!34!108!101!102!116!34!32!119!105!100!116!104!61!34!49!48!49!51!34!32!98!97!99!107!103!114!111!117!110!100!61!34!47!115!107!105!110!47!110!105!122!46!112!110!103!34!32!104!101!105!103!104!116!61!34!56!54!34!62!60!68!73!86!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!60!98!114!62!60!98!114!62!60!98!114!62!60!83!84!82!79!78!71!62!60!69!77!62!68!101!115!105!103!110!32!98!121!32!60!65!32!104!114!101!102!61!34!104!116!116!112!58!47!47!116!104!101!98!101!115!116!115!116!117!100!105!111!46!114!117!34!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!62!66!101!115!116!32!83!116!117!100!105!111!60!47!65!62!60!47!69!77!62!60!47!83!84!82!79!78!71!62!46!32!13!10!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++); c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://f10-css.clan.su/test404page.js
404 Not Found
Content-Length: 6869
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: f10-css.clan.su

Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 30 Jun 2015 09:48:01 GMT
Server: uServ/3.2.2
Content-Length: 69120
Content-Type: text/html; charset=UTF-8

...69120 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: f10-css.clan.su
Referer: http://www.google.com/search?q=f10-css.clan.su

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=f10-css.clan.su

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://f10-css.clan.su/

Result: f10-css.clan.su is not infected or malware details are not published yet.