New scan:

Malware Scanner report for hidup-baru.com

Malicious/Suspicious/Total urls checked
1/0/15
1 page has malicious code. See details below
Blacklists
OK
Malicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL:
->http://www.mynewn.epac.to/
478 websites infected.

The website "hidup-baru.com" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://hidup-baru.com/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: hidup-baru.com
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Mon, 01 Sep 2014 22:58:33 GMT
Location: http://www.mynewn.epac.to/
Server: Apache/2.2.16 (Debian)
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 9cd4d2fe84cd53f46cc3a720c54c334b=d6pnb178474kco69b7se0hesk2; path=/
X-Powered-By: PHP/5.3.3-7+squeeze14
malicious

Scanned pages/files

RequestServer responseStatus
http://hidup-baru.com/
200 OK
Content-Length: 24482
Content-Type: text/html
clean
http://hidup-baru.com/plugins/system/2j_news_slider/jq_last.js
200 OK
Content-Length: 31980
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/system/2j_news_slider/j.e.js
200 OK
Content-Length: 3197
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/system/2j_news_slider/jq.w.js
200 OK
Content-Length: 3771
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/system/jceutilities/js/jceutilities.js?v=224
200 OK
Content-Length: 27809
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/system/mediaobject/js/mediaobject-150.js
200 OK
Content-Length: 3870
Content-Type: application/javascript
clean
http://hidup-baru.com/media/system/js/caption.js
200 OK
Content-Length: 2036
Content-Type: application/javascript
clean
http://ajax.googleapis.com/ajax/libs/jquery/1.6/jquery.min.js
200 OK
Content-Length: 91668
Content-Type: text/javascript
clean
http://hidup-baru.com/modules/mod_fpss/includes/js/jquery.fpss.js
200 OK
Content-Length: 4899
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/content/ja_tabs/ja_tabs.js
200 OK
Content-Length: 12303
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/content/highslide/highslide-with-html.js
200 OK
Content-Length: 62871
Content-Type: application/javascript
malicious
Malicious code - confirmed by antiviruses (see below)



var hs = {
graphicsDir : 'plugins/content/highslide/graphics/',
restoreCursor : 'zoomout.cur', expandSteps : 10, expandDuration : 250, restoreSteps : 10,
restoreDuration : 250,
marginLeft : 15,
marginRight : 15,
marginTop : 15,
marginBottom : 15,
zIndexCounter : 1001,
restoreTitle : 'Click to close image, click and drag to move. Use arrow keys for next and previous.',
loadingText : 'Loading...',
loadingTitle : 'Cl
... 3582 bytes are skipped ...
ody>.*?$', 'i'), '$1');
}
}
hs.getElementByClass(this.content, 'DIV', 'highslide-body').innerHTML = s;
this.onLoad();
for (var x in this) this[x] = null;
}
};
var HsExpander = hs.Expander;

hs.addEventListener(document, 'mousedown', hs.mouseClickHandler);
hs.addEventListener(document, 'mouseup', hs.mouseClickHandler);
hs.addEventListener(window, 'load', hs.preloadImages);
hs.addEventListener(window, 'load', hs.preloadAjax)

Antivirus reports:

AntiVir
JS/Agent.CB.5
Avast
JS:Redirector-AKA [Trj]
TrendMicro-HouseCall
TROJ_GEN.F47V0328
Comodo
TrojWare.JS.Agent.TC
McAfee-GW-Edition
Heuristic.BehavesLike.JS.Suspicious.J
DrWeb
JS.Redirector.188
GData
JS:Redirector-AKA
ESET-NOD32
JS/Redirector.NJG

http://hidup-baru.com/plugins/content/highslide/swfobject.js
200 OK
Content-Length: 6888
Content-Type: application/javascript
clean
http://hidup-baru.com/plugins/content/highslide/do_cookie.js
200 OK
Content-Length: 2457
Content-Type: application/javascript
clean
http://hidup-baru.com/templates/oscar/script.js
200 OK
Content-Length: 11054
Content-Type: application/javascript
clean
http://facenama.com/popup.php?u=1062461
200 OK
Content-Length: 2902
Content-Type: text/javascript
clean

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=hidup-baru.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hidup-baru.com/

Result: hidup-baru.com is not infected or malware details are not published yet.