Author Topic: Is this Live Blackhole exploit kit detected?  (Read 1501 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Is this Live Blackhole exploit kit detected?
« on: April 04, 2012, 04:37:10 PM »
See: htxp://urlquery.net/report.php?id=38096
and
htxp://zulu.zscaler.com/submission/show/0a5bb3cbf584e2ce46bf788e3ba966c0-1333549822
detection so far: htxps://www.virustotal.com/file/cf15c31858c2121be98f4b538241501fffd9e4dd5e94720c059a15dac8814276/analysis/

For protection against vulnerabilties exploited by blackhole exploit kit, check your pc for latest OS and third party software updated and patches here:
http://secunia.com/vulnerability_scanning/online/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Is this Live Blackhole exploit kit detected?
« Reply #2 on: April 04, 2012, 11:29:43 PM »
Going back there to-day with DrWeb's URL checker, I get a suspicious probably infected:

Checking: htxp://showthread.ph
Engine version: 7.0.1.2210
Total virus-finding records: 2775931
File size: 6769 bytes
File MD5: 4ef0d9b7588486e961dec41257f90bba

hxtp://showthread.ph - archive JS-HTML
>htxp://showthread.ph/JSTAG_1[531][391] - Ok
>htxp://showthread.ph/JSTAG_2[8ed][681] - Ok
>hxtp://showthread.ph/JSTAG_3[fa3][1ab] - Ok
>hxtp://showthread.ph/JSTAG_4[1176][37a] - Ok
>htxp://showthread.ph/JSTAG_5[1518][3a4] - Ok
>htxp://showthread.ph/JSTAG_6[18f6][dd] - Ok
>htxp://showthread.ph/JSTAG_7[19ff][55] - Ok
>htxp://showthread.ph/JSTag_8[8f2][67c] - Ok
>htxp://showthread.ph/JSTag_9[fa8][1a6] - Ok
>htxp://showthread.ph probably infected with SCRIPT.Virus
>hxtp://showthread.ph/JSTag_10[117b][375] - Ok
>htxp://showthread.ph/JSTag_11[151d][39f] - Ok
htxp://showthread.ph - Ok

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!