AlienVault has IP address as actively malicious Threatscore 2 on a scale of 7 Seen first/last on June 28
Malware link blocked by Google Safebrowsing: htxp://2014yingyin.com/
idem htxp://www.20wq.com - htxp://www.067t.com/ - htXp://ershudy.com/
Custom errors:Fail and two warnings on: https://asafaweb.com/Scan?Url=ttkkdy.com
External link from source code blocked: htxp://www.wuyuetian2015.com
not all indexes of the objs array contains data - undefined function p.getElementsByTagName
error: undefined variable p → http://jsunpack.jeek.org/?report=e98f1a1c20148fe2d45bf99d8f0edd1e859061ab
Link is for security research only - open up with NoScript extension active in browser and inside a VM/sandbox!
JS/Redir.gen is a program that appears to be legitimate, but in fact does something malicious. Which may be installed for malicious purposes by an attacker allowing access to your computer from remote locations, stealing passwords, Internet banking and personal data. It is a security threat and should be removed from your system immediately.
Symptoms
When you run a program which attached a JS/Redir.gen, you may not realize that your data and file are in danger. Here are a few symptoms that your computer might be infected by JS/Redir.gen: Computer runs slowly than before.
Wallpaper and other background settings auto changing.
Mouse pointer disappear
Programs auto loading and unloading.
Windows auto closing.
Internet accounts information changing.
E-mail client auto sending messages to all user´s contacts list.
Quote credits "av downloadatoz".
But JS/Redir.MA.gen seems now closed ->: http://support.clean-mx.de/clean-mx/viruses?id=9119270
Hoster not listed: http://www.tcpiputils.com/browse/ip-address/107.149.121.224 but is a darknet, read here:
http://www.webhostingtalk.com/showthread.php?t=1241194