New scan:

Malware Scanner report for wir-fakir.ru

Malicious/Suspicious/Total urls checked
0/1/8
1 page has suspicious code. See details below
Blacklists
OK
Malicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL. The chain of malicious redirects found:
->http://goo.gl/qsao2y
3141 websites infected.
->http://glbonus.in/?partner=pashkela
122 websites infected.
->http://goldline.pro?partner=pashkela
120 websites infected.

The website "wir-fakir.ru" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://www.wir-fakir.ru/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: www.wir-fakir.ru
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 28 May 2014 03:19:02 GMT
Location: http://goo.gl/qSaO2y
Server: nginx
Content-Type: text/html; charset=iso-8859-1
malicious
URL: http://goo.gl/qSaO2y
(imitation of visitor from search engine)


GET /qSaO2y HTTP/1.1
Host: goo.gl
Referer: http://www.google.com/search?q=redirect+check2
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Connection: close
Date: Wed, 28 May 2014 03:19:02 GMT
Pragma: no-cache
Location: http://glbonus.in/?partner=Pashkela
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Alternate-Protocol: 80:quic
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
malicious
URL: http://glbonus.in/?partner=Pashkela
(imitation of visitor from search engine)


GET /?partner=Pashkela HTTP/1.1
Host: glbonus.in
Referer: http://www.google.com/search?q=redirect+check3
HTTP/1.1 302 Found
Connection: close
Date: Wed, 28 May 2014 03:19:23 GMT
Location: http://goldline.pro?partner=Pashkela
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 220
Content-Type: text/html; charset=iso-8859-1
malicious

Scanned pages/files

RequestServer responseStatus
http://www.wir-fakir.ru/
200 OK
Content-Length: 8358
Content-Type: text/html
suspicious
Suspicious code found

</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV></FONT></STRONG>
<P><A href="http://www.odnoklassniki.ru/group/51981983678625">
<IMG id=iuleft000001 border=0 hspace=0 alt="" src="pics/iuleft000001.jpg"></A>
&nbsp;&nbsp;
</P>
<P><A href="http://vk.com/club56282648">
<IMG id=iuleft000002 border=0 hspace=0 alt="" src="pics/iuleft000002.jpg"> </A>
</P>
<DIV>

http://www.wir-fakir.ru/highslide.js
200 OK
Content-Length: 34831
Content-Type: application/x-javascript
clean
http://www.wir-fakir.ru/standardista-table-sorting.js
200 OK
Content-Length: 19383
Content-Type: application/x-javascript
clean
http://www.wir-fakir.ru//yandex.st/share/share.js/
HTTP/1.1 302 Found
Connection: close
Date: Wed, 28 May 2014 03:19:03 GMT
Location: http://err.agava.ru/vh/404.html
Server: nginx
Content-Type: text/html; charset=iso-8859-1
clean
http://err.agava.ru/vh/404.html
200 OK
Content-Length: 12338
Content-Type: text/html
clean
http://err.agava.ru/vh/js/main.js
200 OK
Content-Length: 34164
Content-Type: application/x-javascript
clean
http://www.wir-fakir.ru/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Wed, 28 May 2014 03:19:03 GMT
Location: http://err.agava.ru/vh/404.html
Server: nginx
Content-Type: text/html; charset=iso-8859-1
clean
http://err.agava.ru/test404page.js
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Wed, 28 May 2014 03:36:30 GMT
Location: http://err.agava.ru/vh/404.html
Server: nginx/0.7.67
Content-Length: 161
Content-Type: text/html
clean

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=wir-fakir.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://wir-fakir.ru/

Result: wir-fakir.ru is not infected or malware details are not published yet.