TrojWare.JS.Iframe.GJ detected as JS;Iframe-DOI[Trj]

See: https://www.virustotal.com/nl/url/55ca4ac7566a77920e2fabc6a9198098d8cb97a89b92c70c3a1cefdcb0ab6399/analysis/1406922000/
Suspicious iframes detected:
Object: htxp://fmcarbscollege.in/fmcarbscollege.in/%28S%28hxxgad55sfq3yf3sp5dmklnt%29%29/Default1.aspx?access=denied&ReturnUrl=%2Ffmcarbscollege.in%2FSeo0apc554s553sendweqbuz5%2FDefault1.aspx
SHA1: ea628ad8644aea5c3078f092ee34380afcb9f5f4
Name: TrojWare.JS.Iframe.GJ
100/100 malicious: http://zulu.zscaler.com/submission/show/497df73973baed7d558eda04451e19d4-1406922482

We are being protected by the avast! Webshield.

pol

TrojWare.HTML.Redirect.MOBI detected as JS:Redirector-BDX[Trj] by the avast! Webshield.
We are being protected.
See: http://www.reputationauthority.org/domain_lookup.php?ip=aztimes.ws&Submit.x=16&Submit.y=8&Submit=Search
Trojans detected:
Object: htxp://aztimes.ws/siyaset/60-sevinc-babayeva-oldu.html
SHA1: 990b63d2166287d22e86e940dc553d0ec5ee8a52
Name: TrojWare.HTML.Redirect.MOBI
3 scanners flag here: https://www.virustotal.com/nl/url/4c7b496f205f18d168e580818f3b338a578fc09f07d853edcb683b2cf658fd57/analysis/
Site Potentially Harmful: http://sitecheck.sucuri.net/results/aztimes.ws
65/100 suspicious: http://zulu.zscaler.com/submission/show/4193d477e09d516a03bf4b53a57000d1-1406995794 *
Site is vulnerable to exploits a PHP code injection vulnerability DataLife Engine.
The vulnerability exists in preview.php, due to an insecure usage of preg_replace() with the e modifier, which allows to inject arbitrary php code, when the template in use contains a [catlist] or [not-catlist] tag. (info redits: Offensive Security)
External link flagged: https://www.virustotal.com/nl/url/c4ad4d2c686a09dffb5724aa43a496648dacc4628837a583e79739ed550e11bf/analysis/
iFrame check scan result: Suspicious

Update -
Malware still detected here: https://app.webinspector.com/public/reports/show_website?result=3&site=http%3A%2F%2Fagropilot.home.pl
https://www.virustotal.com/nl/url/fbe0fc05d5001458432c235bcf05ed70ea9e1b6593ce91bbbf1cc9e57408a2c6/analysis/#additional-info
Flagged as infected: http://sitecheck.sucuri.net/results/agropilot.home.pl
via List of iframes included
htxp://agropilot.com.pl/counter.php → https://www.virustotal.com/nl/ip-address/188.128.214.68/information/

polonus

Update: This is a suspicious page according to Comodo’s SiteInspector and website blocked by Bitdefender’s TrafficLight
Result for 2015-04-22 18:51:56 UTC
Website: htxp://adiramot.com
Checked URL: htxp://adiramot.com/adiramot_eldadshrem.html
Suspicious code detected:
Object: htxp://alkar-usridu.com/cache/js-e89700f9de326b9b6e61eb117f771a4b.php
SHA1: 2175cf2602d3246e70be34cde1307713ac537b57
Name: Suspicious-WI.
Suspicious iframes detected:
Object: htxp://adiramot.com/adiramot_eldadshrem.html
SHA1: 339b4825a6a268c6df8eceb26adc62c4d64ec32a
Name: TrojWare.JS.Iframe.GJ
See: https://www.virustotal.com/en/url/bfe45780c206d0a2b8f8fdf2af1e794b6a644ca2416520b962688258d42f307f/analysis/

34 files detected as Severity: Malicious
Reason: Detected reference to blacklisted domain
Details: Detected reference to malicious blacklisted domain wXw.adiramot.com

Yandex blocks: https://yandex.com/infected?l10n=en&url=adiramot.com&redircnt=1429734150.1

Sucuri misses: https://sitecheck.sucuri.net/results/adiramot.com

Avast detects HTML:Iframe-ZG [Trj] on -adiramot_eldadshrem.html

polonus