Malicious defacement on website detected?

See: https://www.virustotal.com/nl/url/9563a58c2327e6896b5e1b0aafb283de7ec502b730194850bfc20119ea5360fa/analysis/
This is particular that VT has it - where Quttera fails: http://quttera.com/detailed_report/tbwc.co.il
but Sucuri flags:
ISSUE DETECTED DEFINITION INFECTED URL
Defacement MW:DEFACED:01 -http://tbwc.co.il
Defacement MW:DEFACED:01 -http://tbwc.co.il/404javascript.js
Web site defaced. Details: http://sucuri.net/malware/entry/MW:DEFACED:01
Hacked By Rebel Team Hackers,
Session fixation vulnerability in the Sessions subsystem in PHP and http://www.scip.ch/en/?vuldb.76015
and https://www.vulnerabilitycenter.com/#!vul=50699
inside code link has a server down- -http://zero-sec.in

polonus

your VT url scan was 5 months old … try again

html scan
https://www.virustotal.com/en/file/d9d7d6398023675b2315f65ed964cdf02b68a7e2b01266a9b82af033c0704dad/analysis/1439324710/

But my dear Pondus, the site is still hacked and defaced.
Never heard of a benevolent defacement: http://toolbar.netcraft.com/site_report?url=http://tbwc.co.il
and -coco.ns.cloudflare.com should do a better job of protecting the website tghey host or what goes on from their servers.

Who wants his website hosted there as there was a history of Zeus launched up from there (now AS is Zeus free),
but still spam and other abuse galore.
This report also has been cleansed:

COCO.NS.CLOUDFLARE.COM

Statistics on COCO.NS.CLOUDFLARE.COM have not been pubished yet by KnujOn. The information may be pending if this page was linked from within KnujOn.com. Otherwise the search has been logged and will be researched. You may find some information below that is useful.


Very suspicious, they wanted to brush up their reputation? What was left of the webpage cache was-
10+ items - NS.CLOUDFLARE.COM were reported to KnujOn in spam …
Domain Instances First Time Last Time
-alimova.com 2 5/29/2014 6/3/2014
-bmcpa.net 7 4/27/2014 5/5/2014 etc.
Some-one does not want to give the real CloudFlare facts out!

Damian

But my dear Pondus, the site is still hacked and defaced.
yes, but when able to we should provide fresh info ;)