Avast WEBforum

Other => Viruses and worms => Topic started by: polonus on February 14, 2016, 04:54:48 PM

Title: Registered and active website hacked & defaced, also suspended?
Post by: polonus on February 14, 2016, 04:54:48 PM
See: http://killmalware.com/alias2.com/#
Scanner output:
Scanning -http://alias2.com/ ...
Script loaded: -https://w.soundcloud.com/player/assets/widget-02740948.js
Status: success
Script loaded: -https://w.soundcloud.com/player/assets/layouts/error-698b3c1d.js
Script loaded: -https://ssl.google-analytics.com/ga.js
Script loaded: -https://sb.scorecardresearch.com/beacon.js
Script loaded: -https://w.soundcloud.com/player/assets/layouts/single-sound-37611a39.js
Re: http://toolbar.netcraft.com/site_report?url=http://alias2.com
Hostgator suspended page: -http://suspended.hostgator.com/js/simple-expand.min.js
http://toolbar.netcraft.com/site_report?url=http://192.254.234.25
See also https://whois.domaintools.com/alias2.com

Hacked iFrame detected: <iframe width="0" height="0" scrolling="no" frameborder="no" src="https://w.soundcloud.com/player/?url=-https://soundcloud.com/defjam/2-chainz-wiz-khalifa-we-own-it&amp;auto_play=true&amp;show_artwork=true"></iframe>
Three SRI issues with script and two with stylesheets here:Scripts 3 issues
Tag   Result
<script src="-https://a-v2.sndcdn.com/assets/vendor-59109-60ff090.js"></script>    Missing SRI hash
<script src="-https://a-v2.sndcdn.com/assets/views-70612-0966a5c.js"></script>    Missing SRI hash
<script src="-https://a-v2.sndcdn.com/assets/app-83e9f-a122c6c.js"></script>    Missing SRI hash
Stylesheets 2 issues
Tag   Result
<link rel="stylesheet" href="-https://style.sndcdn.com/css/interstate-0ab59479718c8235122cad6b16a66953d725c43a.css">    Missing SRI hash
<link rel="stylesheet" href="-https://a-v2.sndcdn.com/assets/css/app-1997baad.css">    Missing SRI hash

Not a hacker with security in mind  :D , while here they may be tracking on us through that link:
Script loaded: -https://ssl.google-analytics.com/ga.js
Script loaded: -https://sb.scorecardresearch.com/beacon.js

polonus (volunteer website security analyst and website error-hunter)