New scan:

Malware Scanner report for ravo-bus.ru

Malicious/Suspicious/Total urls checked
0/0/15
Blacklists
OK
Malicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL. The chain of malicious redirects found:
->http://alfsystem.com.my/includes/domit/1.php
888 websites infected. alfsystem.com.my is marked by Google as suspicious.
->http://www.csra.de/includes/domit/1.php
346 websites infected. www.csra.de is marked by Google as suspicious.

The website "ravo-bus.ru" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/10
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://ravo-bus.ru/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: ravo-bus.ru
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 302 Found
Cache-Control: max-age=2592000
Connection: close
Date: Sun, 31 Aug 2014 17:32:19 GMT
Location: http://alfsystem.com.my/includes/domit/1.php
Server: nginx
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Tue, 30 Sep 2014 17:32:19 GMT
X-Powered-By: PHP/5.3.27
malicious
URL: http://alfsystem.com.my/includes/domit/1.php
(imitation of visitor from search engine)


GET /includes/domit/1.php HTTP/1.1
Host: alfsystem.com.my
Referer: http://www.google.com/search?q=redirect+check2
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sun, 31 Aug 2014 17:32:19 GMT
Location: http://www.csra.de/includes/domit/1.php
Server: Apache
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.3.23
malicious

Scanned pages/files

RequestServer responseStatus
http://ravo-bus.ru/
200 OK
Content-Length: 31678
Content-Type: text/html
clean
http://ravo-bus.ru/media/system/js/caption.js
200 OK
Content-Length: 1965
Content-Type: application/javascript
clean
http://ravo-bus.ru/media/zoo/libraries/jquery/jquery.js?ver=20120209
200 OK
Content-Length: 94153
Content-Type: application/javascript
clean
http://ravo-bus.ru/modules/mod_zooitem/mod_zooitem.js?ver=20120209
200 OK
Content-Length: 300
Content-Type: application/javascript
clean
http://ravo-bus.ru/cache/widgetkit/widgetkit-a5d79231.js
200 OK
Content-Length: 13158
Content-Type: application/javascript
clean
http://ravo-bus.ru/novosti/
200 OK
Content-Length: 16832
Content-Type: text/html
clean
http://ravo-bus.ru/media/widgetkit/js/jquery.js
200 OK
Content-Length: 93828
Content-Type: application/javascript
clean
http://ravo-bus.ru/contact.html
200 OK
Content-Length: 12336
Content-Type: text/html
clean
http://ravo-bus.ru//api-maps.yandex.ru/services/constructor/1.0/js/?sid=mAdI-aUTzPxUhsPWK4q4c1tvkTWo0-eT&width=600&height=450/
404 Not Found
Content-Length: 20165
Content-Type: text/html
clean
http://ravo-bus.ru/avtobusy-dlya-ekskursij-i-turov.html
200 OK
Content-Length: 14726
Content-Type: text/html
clean
http://ravo-bus.ru/avtobus-dlya-shkolnikov.html
200 OK
Content-Length: 17581
Content-Type: text/html
clean
http://ravo-bus.ru/avtobusy-na-svadbu.html
200 OK
Content-Length: 16959
Content-Type: text/html
clean
http://ravo-bus.ru/razvozka-sotrudnikov.html
200 OK
Content-Length: 16724
Content-Type: text/html
clean
http://ravo-bus.ru/avtobus-dlya-vypusknikov.html
200 OK
Content-Length: 16665
Content-Type: text/html
clean
http://ravo-bus.ru/vip-avtobusy.html
200 OK
Content-Length: 11296
Content-Type: text/html
clean

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ravo-bus.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ravo-bus.ru/

Result: ravo-bus.ru is not infected or malware details are not published yet.