Avast WEBforum

Other => Viruses and worms => Topic started by: polonus on January 23, 2021, 02:39:18 PM

Title: Redirect shown to be suspicious by Virus Total. Is it?
Post by: polonus on January 23, 2021, 02:39:18 PM
Re: https://urlscan.io/result/10589aed-3513-4ce8-9caa-9d2867f3b49b/
Then: https://www.virustotal.com/gui/url/b3fe0e2efe74e418f5d9eebf0936efaf27437f6056ea9cd04ce57555db458bd0/detection
(one to flag) and 2 negative community votes:
https://www.virustotal.com/gui/ip-address/185.128.34.116/detection
Various apk android malcode detections: https://www.virustotal.com/gui/ip-address/185.128.34.116/relations
and script issues: -> Results from scanning URL: hxtps://code.jquery.com/jquery-3.3.1.min.js
Number of sources found: 436
Number of sinks found: 80

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
Title: Re: Redirect shown to be suspicious by Virus Total. Is it?
Post by: Asyn on January 23, 2021, 02:47:24 PM
-> https://sitecheck.sucuri.net/results/easywinonline.xyz
Title: Re: Redirect shown to be suspicious by Virus Total. Is it?
Post by: polonus on January 23, 2021, 02:58:59 PM
Thanks Asyn, helpful, better to steer away from all xyz ending domains.

This script seems active there: https://urlscan.io/result/39f013b3-c138-4bcc-9ae0-a90efb763abf/
Nothing found there, but any other use of this Amazon CloudFront dot net script is strictly forbidden.

Relation with Results from scanning URL: -https://jakethijaber.xyz/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.70
Number of sources found: 2
Number of sinks found: 1  (warning on connection time-out

So what is really going on at the other side of your screen  :-[

polonus

Title: Re: Redirect shown to be suspicious by Virus Total. Is it?
Post by: Asyn on January 23, 2021, 03:15:48 PM
As you speak German, see: https://www.antispam-ev.de/forum/showthread.php?40484-niederl%E4ndische-Riesenspams&p=445040&viewfull=1#post445040
Title: Re: Redirect shown to be suspicious by Virus Total. Is it?
Post by: Pondus on January 23, 2021, 04:18:10 PM
Quote
-> https://sitecheck.sucuri.net/results/easywinonline.xyz
No scan results from a url that is down   https://downforeveryoneorjustme.com/easywinonline.xyz


Title: Re: Redirect shown to be suspicious by Virus Total. Is it?
Post by: polonus on January 23, 2021, 06:19:13 PM
Gigantic spammer been taken down,

polonus