See: http://quttera.com/detailed_report/djgol.info
Files detected: “Detected reference to malicious blacklisted domain -djin.in”
VT does not have it: https://www.virustotal.com/nl/url/ddef4c31c1e8880cdaaefe7ddb4f445186a13f65843cad84cbad323239d19aa5/analysis/#additional-info
Sucuri’s does not flag: https://sitecheck.sucuri.net/results/djgol.info#sitecheck-details
urlquery dot net does not either: http://urlquery.net/report.php?id=1452178095881
External link flagged here: https://www.virustotal.com/nl/domain/admaster.union.ucweb.com/information/
But again no detections here: https://www.virustotal.com/nl/url/b5e5484d3f0808ea069b76d4c2b1740a0aadf19c31436be9b3b9ee45cfbed431/analysis/
Flagged as suspicious by Quttera’s: admaster.union.ucweb.com/js/union_html5_sdk.js
Severity: Potentially Suspicious
Reason: Suspicious JavaScript code injection.
Details: Procedure: + has been called with a string containing hidden JavaScript code .
Threat dump see: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fadmaster.union.ucweb.com%2Fjs%2Funion_html5_sdk.js
Threat dump MD5: D0A10BEEF1F6044EA56BD8750D042AE9
File size[byte]: 19316
File type: ASCII
Page/File MD5: 7BAF363852B444DDA69A376AAAEFE355
Blocked by adblock filter: -http://slot.union.ucweb.com/ & -http://www.googletagmanager.com/gtm.js?id=GTM-NZ7GDJ
General IP badness history: https://www.virustotal.com/nl/ip-address/69.64.47.59/information/
polonus