Author Topic: Can some1 check this site?  (Read 2671 times)

0 Members and 1 Guest are viewing this topic.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Can some1 check this site?
« on: August 26, 2010, 10:42:33 PM »
http://www.xboxkinect.dk/               can some1 check this site about viruses etc.?
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Can some1 check this site?
« Reply #1 on: August 26, 2010, 10:51:49 PM »
very easy to do, you go here   www.virustotal.com   then click " Submit a URL " and put in the URL, wait for the scan to finish  ;)
you can also use this  http://www.unmaskparasites.com/ and this http://www.urlvoid.com/

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Can some1 check this site?
« Reply #2 on: August 26, 2010, 11:04:35 PM »
very easy to do, you go here   www.virustotal.com   then click " Submit a URL " and put in the URL, wait for the scan to finish  ;)
you can also use this  http://www.unmaskparasites.com/ and this http://www.urlvoid.com/

thank you
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can some1 check this site?
« Reply #3 on: August 27, 2010, 02:11:04 AM »
Hi Left123,

As you know from this forum an url that might be infected or is suspicious of having malware should be given here as htxp or wXw so it becomes non-click through for the unaware that might get infevted by clicking it.
The requested URL was analyzed and found legitimate,

Heavy tracking though. but benign: http://jsunpack.jeek.org/dec/go?report=9b64a89ee2f24ee8aa76cba14a30778cca10a8aa
Web server details
Scan for: htxp://www.xboxkinect.dk/
Hostname: wXw.xboxkinect.dk
IP Address: 208.53.147.171 (.)
Date: 26-08-2010 19:58

Running on: Apache/2.2.16

System info: (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8b mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8
Powered by: PHP/4.4.7

Web Application details:
Application: WordPress 3.0.1
Google Adsense installed: pub-9348221948414274

Wordpress details:
Wordpress Version: WordPress 3.0.1
Wordpress version (source): 3.0.1
Wordpress theme: htxp://www.xboxkinect.dk/wp-content/themes/super-adsense-xbox/

Wordpress internal path: /home/xboxkine/public_html/wp-content/themes/super-adsense-xbox/index.php
CheckGOOD. Wordpress current with latest version 3.0.1.


Wordpress version detection:
Version >= 2.9 for wp-includes/js/wp-ajax-response.js
Version >= 2.8 for wp-includes/js/hoverIntent.js
Version >= 2.9 for wp-includes/js/wp-lists.js

References:
http://sucuri.net/?page=docs&title=wordpress-hardening
http://sucuri.net/?page=docs&title=fingerprinting-web-apps
Javacript included

Remote Javascript included: htxp://track3.mybloglog.com/js/jsserv.php?mblID=2007011502093135

Remote Javascript included: htxp://pagead2.googlesyndication.com/pagead/show_ads.js

Remote Javascript included: htxp://pub.mybloglog.com/comm2.php?mblID=2007011502093135&c_width=160&c_sn_opt=y&c_rows=8&c_img_size=h&c_heading_text=&c_color_heading_bg=FAFFEF&c_color_heading=ffffff&c_color_link_bg=FAFFEF&c_color_link=89CF00&c_color_bottom_bg=FAFFEF
Javacript dump

<script type='text/javascript' src='htxp://track3.mybloglog.com/js/jsserv.php?mblID=2007011502093135'></script>
   <script type="text/javascript"><!--
   google_ad_client = "pub-9348221948414274";
   google_ad_width = 468;
   google_ad_height = 60;
   google_ad_format = "468x60_as";
   google_ad_type = "text";
   google_ad_channel = "1234567891";
   google_color_border = "FFFFFF";
   google_color_bg = "FFFFFF";
   google_color_link = "89CF00";
   google_color_text = "000000";
   google_color_url = "4d7302";
//--></script>
   <script type="text/javascript"
     src="htxp://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
   <script type="text/javascript"><!--
   google_ad_client = "pub-9348221948414274";
   google_ad_width = 160;
   google_ad_height = 600;
   google_ad_format = "160x600_as";
   google_ad_type = "text";
   google_ad_channel = "1234567891";
   google_color_border = "FFFFFF";
   google_color_bg = "FAFFEF";
   google_color_link = "89CF00";
   google_color_text = "333333";
   google_color_url = "4d7302";
//--></script>
   <script type="text/javascript"
     src="hxtp://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
<script type="text/javascript" src="htxp://pub.mybloglog.com/comm2.php?mblID=2007011502093135&amp;c_width=160&amp;c_sn_opt=y&amp;c_rows=8&amp;c_img_size=h&amp;c_heading_text=&amp;c_color_heading_bg=FAFFEF&amp;c_color_heading=ffffff&amp;c_color_link_bg=FAFFEF&amp;c_color_link=89CF00&amp;c_color_bottom_bg=FAFFEF"></script>

List of links found

htxp://www.xboxkinect.dk/feed/
htxp://www.xboxkinect.dk/feed/rss/
htxp://www.xboxkinect.dk/feed/atom/
htxp://www.xboxkinect.dk/xmlrpc.php
htxp://www.xboxkinect.dk/2010/08/
htxp://www.xboxkinect.dk/xmlrpc.php?rsd
htxp://www.xboxkinect.dk/wp-includes/wlwmanifest.xml
htxp://www.xboxkinect.dk/
hxtp://www.xboxkinect.dk/page2/
htxp://www.xboxkinect.dk/category/uncategorized/
htxp://www.google.com
htxp://www.xboxkinect.dk/kinect-til-xbox-360/
htxp://www.xboxkinect.dk/category/nyheder/
htxp://www.easywordpress.com/go.php?offer=winniche&amp;pid=3
htxp://www.easywordpress.com/go.php?offer=winniche&amp;pid=9

Blacklisting status

Domain clean by Google Safe Browsing: wXw.xboxkinect.dk

Domain clean by Norton Safe web: wXw.xboxkinect.dk

Domain clean by Sucuri Web Blacklist: wXw.xboxkinect.dk

Domain clean by the Phish Tank: wXw.xboxkinect.dk

Domain clean by the Malware Domain List: wXw.xboxkinect.dk

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!