Author Topic: Live blackhole site was blocked by Google Safebrowsing  (Read 430 times)

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Live blackhole site was blocked by Google Safebrowsing
« on: July 12, 2012, 01:22:50 PM »
See: http://urlquery.net/report.php?id=75427
With various IDS alerts malcious software contains 111 trojans, 53 exploits, 21 bots.

Better to have stayed away from that site and therefore it is being blocked,
trojan Zero-access/Sirefef.pl seems dead since 2012-06-26 00:24:42 had been active for 3.2 hrs,
9 other instances of malware from there now also dead...No file was found at that url,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • avast! Evangelist
  • Super Poster
  • ***
  • Posts: 1303
  • Gender: Male
  • Spartan Warriors
    • Personal Message (Offline)
Re: Live blackhole site was blocked by Google Safebrowsing
« Reply #1 on: July 12, 2012, 03:12:45 PM »
Thanks pol,

This is massively bad!   :o

I take it not active at the moment?
XP Pro SP3 P4 3.2 HT 2GB RAM AIS v 8.0.1489 Secunia PSI version 2.0.0.3003 TREND Micro RUBotted Beta Javacool SpywareBlaster version 5.0 Sandboxie v. 3.76 WOT (Web Of Trust) Browser reputation-based add-on http://www.mywot.com/

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Live blackhole site was blocked by Google Safebrowsing
« Reply #2 on: July 12, 2012, 03:16:53 PM »
That could mean one of two things. Taken down or neatly blocked by the avast network shield. Think the first option!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Live blackhole site was blocked by Google Safebrowsing
« Reply #3 on: July 12, 2012, 03:32:36 PM »
This is what I have: Оффлайн (not active - Russian = offline)
12.07.12 19:07   26.06.2012 01:20    flyhighhavefun dot com    194.50.116.64   trojan ZeroAccess/Sirefef
Read this write-up: http://www.kindsight.net/en/blog/2012/06/28/malware-analysis-new-cc-protocol-for-zeroaccesssirefef
link author and link from: By Kevin McNamee, Kindsight Security Labs,

polonus
« Last Edit: July 12, 2012, 03:37:41 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Live blackhole site was blocked by Google Safebrowsing
« Reply #4 on: July 14, 2012, 03:41:53 PM »
See: http://urlquery.net/report.php?id=90275
Good it is being blocked by Google Safebrowsing: http://www.google.com/safebrowsing/diagnostic?site=http%3A//www.dicodufutur.org/wp-signup.php%3Fnew%3Ddicodufutur.org

The location line in the header above has redirected the request to: htxp://www.dicodufutur.org/wp-signup.php?new=dicodufutur.org

AS Name: OVH OVH Systems
IPs allocated: 737024
Blacklisted URLs: 3460

Hosts...
...malicious URLs? Yes 
...badware? Yes 
...botnet C&C servers? Yes 
...Zeus botnet servers? Yes 
...Current Events? Yes 
...phishing servers? Yes 

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!