Is this malcious code being detected?

Not here: http://zulu.zscaler.com/submission/show/863f5f943bb946212a2b64cc26dbff4f-1359652595
Here it is being detected: http://sitecheck.sucuri.net/results/wa2ise.com
See attached image
Not flagged here: https://www.virustotal.com/url/288c8ec69fa40c52b189620ff6049f5aef60eeb548ce1657963bd290561c5900/analysis/1359653732/
Detected and warning here: http://www.avgthreatlabs.com/sitereports/domain/wa2ise.com/
12 potentially suspicious files found here: http://quttera.com/detailed_report/wa2ise.com

polonus

give me 5min and i will find out. :wink:

Well no avast flags…that is for sure…but from other domains on that IP there is a variety of malware launched, like: JS/Redirector.xbma, JS/iFrame.AV.1, JS/BlacoleRef.W.26, JS/Clicker.CA (various), JS/iFrame.czo, JS/iFrame.ZM, all this malware alive and kicking at the moment…

polonus

nope :-\

http://virusscan.jotti.org/en/scanresult/1d3f2696bd444a3dafb0d2c689922771f4105d35
https://www.virustotal.com/file/893d5121ebdc8ac706358cae81884b8a4d9d9fc07bc96e9099476ee528ee4f63/analysis/

Arousing suspicion is this in the code

  < sc&#8203;ript type="text/javasc&#8203;ript" language="javasc&#8203;ript"  

Well all that was reason enough to report this to virus AT avast dot com and maybe they can block also the other malicious domains from 67.195.61.65 as URL;Mal. This from that IP avast does detect: https://www.virustotal.com/file/45764ea18e87ea2fe66c2259cbf281491947b39285e404b71e7d4f5fb6090315/analysis/
Also consider from that site external references: http://www.google.com/safebrowsing/diagnostic?site=pw2.netcom.com
& http://www.google.com/safebrowsing/diagnostic?site=l.yimg.com

polonus

http://wepawet.iseclab.org/view.php?hash=0672ca54fec4ffdbd01284246eebfb29&type=js
http://www.urlvoid.com/scan/apartmentsforyou.it/
http://urlquery.net/report.php?id=907300