New scan:

Malware Scanner report for ultra.inc.ru

Malicious/Suspicious/Total urls checked
0/1/12
1 page has suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.ultra.inc.ru/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 15 Dec 2014 13:56:11 GMT
Location: http://kokteil.net/
Server: nginx/1.6.2
Vary: Accept-Encoding
Content-Length: 309
Content-Type: text/html; charset=iso-8859-1
clean
http://kokteil.net/
200 OK
Content-Length: 28515
Content-Type: text/html
suspicious
Suspicious code found

<div id="searchcont">
<form method="get" id="navSearch" name="navSearch" action="http://kokteil.net">
<input type="hidden" autocomplete="off" class="hiddenInput" />

<span class="uiSearchInput textInput">
<span>

<div class="inp-w"><div class="width-setter">

<input onblur="if(this.value=='')this.value=this.defaultValue;" onfocus="if(
... 237 bytes are skipped ...
amp;quot;placeholder&quot;)) &#123;s.focus(); return false;&#125;" autocomplete="off" tabindex="" spellcheck="false" value="" title="Поиск" />
<button type="submit" title="Поиск">

<span class="hidden_elem">Поиск</span>
</button>
</div></div>
</span>
</span>
</form>

</div>

http://kokteil.net/wp-includes/js/jquery/jquery.js?ver=1.11.0
200 OK
Content-Length: 96402
Content-Type: application/javascript
clean
http://kokteil.net/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 7200
Content-Type: application/javascript
clean
http://kokteil.net/wp-content/themes/cell/js/_script-2.js?ver=3.9.3
200 OK
Content-Length: 159276
Content-Type: application/javascript
clean
http://kokteil.net/wp-content/themes/cell/js/script.js?ver=3.9.3
200 OK
Content-Length: 2023
Content-Type: application/javascript
clean
http://kokteil.net/wp-content/themes/cell/includes/paginator/js/paginator3000.js
200 OK
Content-Length: 11816
Content-Type: application/javascript
clean
http://www.ultra.inc.ru//vk.com/js/api/openapi.js?105/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 15 Dec 2014 13:56:13 GMT
Location: http://kokteil.net/vk.com/js/api/openapi.js?105/
Server: nginx/1.6.2
Vary: Accept-Encoding
Content-Length: 338
Content-Type: text/html; charset=iso-8859-1
clean
http://kokteil.net/vk.com/js/api/openapi.js?105/
404 Not Found
Content-Length: 570
Content-Type: text/html
clean
http://kokteil.net/test404page.js
404 Not Found
Content-Length: 570
Content-Type: text/html
clean
http://www.ultra.inc.ru//loginza.ru/js/widget-2.0.js/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 15 Dec 2014 13:56:13 GMT
Location: http://kokteil.net/loginza.ru/js/widget-2.0.js/
Server: nginx/1.6.2
Vary: Accept-Encoding
Content-Length: 337
Content-Type: text/html; charset=iso-8859-1
clean
http://kokteil.net/loginza.ru/js/widget-2.0.js/
HTTP/1.1 404 Not Found
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Mon, 15 Dec 2014 13:56:13 GMT
Pragma: no-cache
Server: nginx/1.7.7
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://kokteil.net/xmlrpc.php
X-Powered-By: PHP/5.3.29
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: ultra.inc.ru

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: ultra.inc.ru
Referer: http://www.google.com/search?q=ultra.inc.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ultra.inc.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ultra.inc.ru/

Result: ultra.inc.ru is not infected or malware details are not published yet.