Author Topic: kerbalspaceprogram.net malware/trojen in the wild  (Read 16749 times)

0 Members and 1 Guest are viewing this topic.

OliPicard

  • Guest
kerbalspaceprogram.net malware/trojen in the wild
« on: March 21, 2013, 09:38:33 PM »
It seems this site hasent been blacklisted by avast. I recently visited this website thinking it was part of kerbalspaceprogram.com however it seems to be a fan site. When looking into the securi site scan this website seems to have malware.

URL visited: kerbalspaceprogram.net/privacy-policy (DO NOT GO TO THIS ADDRESS..)
Affects: Unknown Site Host Affects: Bad plugin on wordpress http://labs.sucuri.net/db/malware/malware-entry-mwiframehd202
Malware type: iFrame injection Diagnosis: http://sitecheck.sucuri.net/results/www.kerbalspaceprogram.net/privacy-policy
Blacklist: Hasent been Blacklisted yet, This seems to be an injection into the wordpress site.

Virus Total Scan: Green https://www.virustotal.com/en-gb/url/448b52271d9c6555f309120eb511f54ca036569924bd3f9c366bcf4b69fef300/analysis/1363898822/
Additional Scans pointing towards possible phishing scam? http://www.phishtank.com/phish_detail.php?phish_id=1768044

Any help on detecting and clearing this up? In addition mods should note that a previous post i had has been put on hold for some strange reason
Thanks
OliPicard
« Last Edit: March 21, 2013, 11:19:39 PM by OliPicard »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: kerbalspaceprogram.net malware
« Reply #1 on: March 21, 2013, 09:46:05 PM »
edit your post and remove www from the link so it is not clickable

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware
« Reply #3 on: March 21, 2013, 09:48:39 PM »
Hi Pondus, Have done as you have requested. (Sorry about that.)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: kerbalspaceprogram.net malware
« Reply #4 on: March 21, 2013, 09:50:07 PM »
Hi Pondus, Have done as you have requested. (Sorry about that.)
Thanks.....then we avoid click accidents   ;)

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware
« Reply #5 on: March 21, 2013, 09:52:22 PM »
Should i run Mbam/CCleaner/Combofix/OTL? :D It may be time for Essexboy!

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware
« Reply #6 on: March 21, 2013, 09:53:33 PM »
should note that sucuri saw this as this type of signature. http://labs.sucuri.net/db/malware/malware-entry-mwiframehd202 MW:IFRAME:HD202
« Last Edit: March 21, 2013, 09:56:03 PM by OliPicard »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: kerbalspaceprogram.net malware
« Reply #7 on: March 21, 2013, 09:57:18 PM »
Should i run Mbam/CCleaner/Combofix/OTL? :D It may be time for Essexboy!
you may do that...  AdwCleaner / Malwarebytes / OTL / aswMBR   ;)
you find the guide at top in this forum section

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware
« Reply #8 on: March 21, 2013, 10:02:31 PM »
Tracing site, Will post anything i can find. First site seems clean until you see its redirecting people to another bit.ly site It seems to be a middleman attack. http://www.phishtank.com/phish_detail.php?phish_id=1768044 note it seems this site may have just been infected. This isnt good.
« Last Edit: March 21, 2013, 10:13:39 PM by OliPicard »

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #9 on: March 21, 2013, 10:15:02 PM »
Running MBAM, shall post log, After that will run aswmbr

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #10 on: March 21, 2013, 10:16:31 PM »
Mbam log
« Last Edit: March 21, 2013, 10:44:17 PM by OliPicard »

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #11 on: March 21, 2013, 10:52:15 PM »
Just tried to run ASWMBR however this poped up and refused to go away.
Also provided this link http://cima.security.comodo.com/report/5203462c9e1a600682aedf312e89f35cb1c7fe9b.htm

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #12 on: March 21, 2013, 10:55:10 PM »
Running OTL shall post log

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #13 on: March 21, 2013, 11:01:33 PM »
That is blocking aswmbr

OliPicard

  • Guest
Re: kerbalspaceprogram.net malware/trojen in the wild
« Reply #14 on: March 21, 2013, 11:03:53 PM »
OTL log + extras log

Shall go ahead and scan ASWMBR now