Only Kaspersky to flag this website? Abuse going on from IP!

Kaspersky found some abuse going on here. Read on.

Vulnerable server header: Outdated Web Server Nginx Found: nginx/1.2.3
Server vuln:

Same IP domains:
IP badness history:
DrWeb JS.Loadpays.2 launched from that IP and latest found: Adware.Downware.2095
htxp:// is in Dr.Web malicious sites list!
My connnection is flagged to be not private here: htxps:// (Privacy error given by Chrome)
Site may be down:
See all the IDS alerts in “Recent reports on same IP/ASN/Domain”
like IDS alert: ET INFO HTTP Request to a * domain, ET INFO DYNAMIC_DNS HTTP Request to Abused Domain *, ET POLICY HTTP Request to a *.tk domain.
Kraken Virus Tracker confirms: myfiler.anchih.pp dot ua,, ns1.lp-dns dot com, Criminals,
This only means to say there is up and active malcode there, no more no less.

DNS Inspection Report:
→ htxp:// is present in the Dr.Web database of unwanted sites!

XSS vuln: Results from scanning URL: htxp://
Number of sources found: 0
Number of sinks found: 123

Results from scanning URL: htxp://
Number of sources found: 38
Number of sinks found: 21 → document,cm.write (as source)

Javascript check:
For security research only, open link with NoScript active in the browser and inside a VM/sandbox.

Code hick-up:
myfiler.anchih.pp dort ua/js/jquery.jcarousel.min.js benign
[nothing detected] (script) myfiler.anchih.pp dot ua/js/jquery.jcarousel.min.js
status: ( 17461 bytes 7f39276f2b5c4d00f2041df89290b1665b6aa577
info: [decodingLevel=0] found JavaScript
And undefined function q.getElementsByTagName
error: undefined variable q
In main.js: undefined variable $ -XSS vuln, see resultsfrom scanning URL: htxp://,/wp-content/mu-plugins/highlander-comments/script.js?m=1414003384j
Number of sources found: 38
Number of sinks found: 12 via Java Lexer using javax annotations

Possibly remote inclusion vulnerability in code link htxp:// (Zend/PHP) - wrap circular 'loop
in myfiler.anchih.pp dot ua/js/jquery.jcarousel.min.js


Update for this domain on IP only flagged by Kaspersky’s:
System Details:
Running on: nginx/1.2.3
Powered by: PHP/5.4.6
Outdated Web Server Nginx Found: nginx/1.2.3
Server configuration and FW warnings for -
Browser Diff. so-called Cloaking alert:
Not equal
Google: 29511 bytes Firefox: 28754 bytes
Diff: 757 bytes

IP badness history:
App downloader issues! PHISH and spam IP listed here:
