See: https://www.virustotal.com/en/url/68182bb4dd8b334ee37b5003b26153d41f7e6dc5a14286c17b3f727830624909/analysis/1426973582/
Suspicious files: /mnt/pages/register?retpath=http%3a%2f%2fqip.ru%2f&utm_source=mainqip&utm_medium=referral&utm_term=title&utm_campaign=main_new_register
Severity: Suspicious
Reason: Detected reference to blacklisted domain
Details: Detected reference to suspicious blacklisted domain -quote.rbc.ru
-/i/gameblock
Severity: Suspicious
Reason: Detected reference to blacklisted domain
/javascript%3A
Severity: Suspicious
Reason: Detected reference to blacklisted domain
Details: Detected reference to suspicious blacklisted domain -quote.rbc.ru
Potentially suspcious: Detected potentially suspicious initialization of function pointer to JavaScript method document.write __tmpvar678006046 = document.write;
[[<script type='text/javascript' language='javascript' > if (window!=window.top) { document.write('<div style="display:none">'); dwrite = document.write; document.write = function() { } } </script>]]
Sucuri does not detect but lists these:
List of iframes included
htxp://r.qip.ru/rb?name=hosting_300x250&jscookie=0
htxp://r.qip.ru/iframe?name=Hosting_subfooter&jscookie=0 infested with Win32:Widget [Trj]
→ http://totalhash.com/analysis/8e1b0993a6e64bfdea6005105b68c809242806cc
polonus