Avast WEBforum

Other => Viruses and worms => Topic started by: polonus on February 13, 2018, 05:59:20 PM

Title: Social engineering malware on website?
Post by: polonus on February 13, 2018, 05:59:20 PM
Reported: https://urlscan.io/result/5b8e53f1-275f-4e4e-9cdf-59d2aac58ef3#behaviour
See: https://www.virustotal.com/nl/url/0f284891a8a8c50df9df168b355aaa02b97ed1e79ddeaa4d054b38be394617f1/analysis/1518538751/
0 on downloaded -> https://www.virustotal.com/nl/file/73b1ce58fa539aab1d6d1424607c5ff60fc5e2f2c0becd3a776f7f4f8f3664b0/analysis/1499921223/
Retirable jQuery libraries: 2 -> http://retire.insecurity.today/#!/scan/ec2308eaa41e8aa5456d9860969d9e18c1b4cc68f8acd64297306a5eedf27bf9

Consider: https://aw-snap.info/file-viewer/?protocol=secure&tgt=uluulupetcafe.sg%2FInvo00%2FDropbo%2Fhome%2Ferror.php&ref_sel=GSP2&ua_sel=ff&fs=1

Site is Google flagged: -https://uluulupetcafe.sg/Invo00/Dropbo/home/dbx/email.png
Nothing now here: http://www.cookie-checker.com/check-cookies.php?url=https%3A%2F%2Fuluulupetcafe.sg

36 blacklisted links: https://quttera.com/detailed_report/uluulupetcafe.sg

Phishing detected: https://yandex.com/infected?l10n=en&url=uluulupetcafe.sg

polonus (volunteer website security analyst and website error-hunter)

polonus