Author Topic: adf.ly is malicious?  (Read 10067 times)

0 Members and 1 Guest are viewing this topic.

Offline danny96

  • Malware Fighter
  • Advanced Poster
  • **
  • Posts: 668
  • No-malware!
adf.ly is malicious?
« on: June 19, 2011, 05:35:02 PM »
I just wanted to download texture pack for minecraft on website www.minecraftforum.net and when I clicked download It wanted to redirect me on adf.ly (as always) but avast! blocked It. I was doing this about 20x times about 1 week ago (with same texture pack) and It was OK. Maybe a false positive?
URL was 178.77.79.79/lang
« Last Edit: June 19, 2011, 05:38:24 PM by danny96 »
Real-time protection and Firewall: COMODO Internet Security 12.0.0.6810 -- Additional Protection: Web Of Trust, Ublock, NoScript, Malwarebytes Premium, Avast! Online Security, Hitman Pro -- OS: Windows 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: adf.ly is malicious?
« Reply #1 on: June 19, 2011, 05:49:38 PM »
Hi danny96,

See why here: http://www.urlvoid.com/scan/adf.ly
There are several exploits hosted on that site, but a lot of the exploits on IP 69.65.43.7 and
69.39.236.36 are "dead" allthough ip status is "up" see: http://hosts-file.net/?s=adf.ly
server2.adf.ly is classified as having status EMD (malware; severity: High Risk),
see http://hosts-file.net/?s=adf.ly


polonus
« Last Edit: June 19, 2011, 06:08:57 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: adf.ly is malicious?
« Reply #2 on: June 19, 2011, 05:50:14 PM »
Report    2011-06-19 17:31:21 (GMT 1)
Website    adf.ly
Domain Hash    97d3881a388d64236c80a94f40d9ce60
IP Address    69.39.236.36 [SCAN]
IP Hostname    server2.adf.ly
IP Country    US (United States)
AS Number    32181
AS Name    ASN-GIGENET - GigeNET
Detections    4 / 23 (17 %)
Status    DANGEROUS

http://amada.abuse.ch/?search=adf.ly
http://hosts-file.net/?s=adf.ly
http://www.malwareblacklist.com/searchClearingHouse.php?search=adf.ly
http://www.phishtank.com/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline danny96

  • Malware Fighter
  • Advanced Poster
  • **
  • Posts: 668
  • No-malware!
Re: adf.ly is malicious?
« Reply #3 on: June 19, 2011, 06:04:26 PM »
Report    2011-06-19 17:31:21 (GMT 1)
Website    adf.ly
Domain Hash    97d3881a388d64236c80a94f40d9ce60
IP Address    69.39.236.36 [SCAN]
IP Hostname    server2.adf.ly
IP Country    US (United States)
AS Number    32181
AS Name    ASN-GIGENET - GigeNET
Detections    4 / 23 (17 %)
Status    DANGEROUS

http://amada.abuse.ch/?search=adf.ly
http://hosts-file.net/?s=adf.ly
http://www.malwareblacklist.com/searchClearingHouse.php?search=adf.ly
http://www.phishtank.com/

I visiting this website daily and no reports yet until now.
Real-time protection and Firewall: COMODO Internet Security 12.0.0.6810 -- Additional Protection: Web Of Trust, Ublock, NoScript, Malwarebytes Premium, Avast! Online Security, Hitman Pro -- OS: Windows 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: adf.ly is malicious?
« Reply #4 on: June 19, 2011, 06:18:31 PM »
Hi danny96,

The malware and website infection landscape is an everchanging one, exploits and silent drive-by-downloads are uploaded and taken down in an ever so quickly changing tempo, your site had a rather good web reputation rating: http://www.mywot.com/en/scorecard/adf.ly but one sees that users already starting reporting spyware, adware, phishing and malware from there, and the bad news has not reached here: http://www.webutation.net/go/review/adf.ly and the name of the game is SWF and that is where the malware exploit tragedy starts there. Good avast protects!
The url you reported served up:  Trojan/Win32.Trojan Horse or a Bifrose variant...

polonus
« Last Edit: June 19, 2011, 06:24:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: adf.ly is malicious?
« Reply #5 on: June 19, 2011, 06:24:11 PM »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: adf.ly is malicious?
« Reply #6 on: June 19, 2011, 10:31:07 PM »
I visiting this website daily and no reports yet until now.

S..t happens. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0