New scan:

Malware Scanner report for xn--e1agobbejapf.com

Malicious/Suspicious/Total urls checked
1/1/4
2 pages have malicious or suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "xn--e1agobbejapf.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
Found
The website redirects visitors to the 3rd-party URL:
->http://internet-ru.com/
internet-ru.com is marked by Google as malicious.

The website "xn--e1agobbejapf.com" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/2
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=xn--e1agobbejapf.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: likebuket.ru

Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Sun, 13 Apr 2014 01:32:23 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 6e5b4e370b764fb73243760515eea680=6ee049ce61bb2b640c03bb3e22b81d22; path=/
X-Powered-By: PHP/5.3.3
Second query (visit from search engine):
GET / HTTP/1.1
Host: likebuket.ru
Referer: http://www.google.com/search?q=likebuket.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Scanned pages/files

RequestServer responseStatus
http://xn--e1agobbejapf.com/
HTTP/1.1 302 Found
Connection: close
Date: Fri, 27 Feb 2015 07:29:39 GMT
Location: http://portalmobi.com/in.cgi?4&group=torrentino--com
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
clean
http://portalmobi.com/in.cgi?4&group=torrentino--com
HTTP/1.1 302 Found
Connection: close
Date: Fri, 27 Feb 2015 07:49:51 GMT
Location: http://internet-ru.com/
Server: nginx
Content-Length: 287
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: dmvgp=4LAhADQAAwArAZ8h8FT__58h8FQrAJ8h8FRAAAEAAACfIfBUAA--; expires=Sat, 27-Feb-2016 07:49:51 GMT; path=/; domain=portalmobi.com
malicious
http://internet-ru.com/
200 OK
Content-Length: 4227
Content-Type: text/html
suspicious
Suspicious code found


<div id="logo">
<h1>Èíòåðíåò&nbsp;ñîåäèíåíèå...</h1>
<table cellpadding="0" cellspacing="0" width="100%">
<tbody><tr>
<td style="padding: 4px 0pt 5px;" width="300">
Ñâÿçü ïðåäîñòàâëåíà ÎÀÎ "Èíòåðíåò Ðó". Ìàãèñòðàëüíûé îïåðàòîð ñåòåâîãî äîñòóïà è àãðåãàòîð ðåãèîíàëüíûõ òåëåêîììóíèêàöèîííûõ ñåòåé.
</td>
<td class="tCenter" style="padding: 0pt 6px;">
<font face="arial" size="2">&
... 65 bytes are skipped ...
X Service Alarm: Ïðåâûøåí ëèìèò îäíîâðåìåííûõ ñîåäèíåíèé. Îòêàç ÁÄ. (Error #1035).<br>
> Çàïðîøåííûé Ñåðâåð ïåðåãðóæåí, èäåò êýøèðîâàíèå òðàôèêà ïî ïðîòîêîëó IPTSV6.&nbsp;&nbsp;<?
echo date("H:i:s Ìñê d.m.Y",time()+3*3600); ?><br>
> Ïîëüçîâàòåëü (IP *************) ïðîâåðåí: ÎÊ. Âûäåëåíèå íîâîãî äèíàìè÷åñêîãî äèàïàçîíà: $time=120 ñåê.<br></font>
</td>
</tr>
</tbody></table>
</div>

http://internet-ru.com/test404page.js
404 Not Found
Content-Length: 292
Content-Type: text/html
clean