Author Topic: avast! Web Shield blocks a Sucuri and jsunpack Site Scan!  (Read 1594 times)

0 Members and 1 Guest are viewing this topic.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34052
  • malware fighter
avast! Web Shield blocks a Sucuri and jsunpack Site Scan!
« on: January 12, 2014, 12:36:55 AM »
This was blocked: http://sitecheck.sucuri.net/results/www.dnps.com/ ( because avast! Web Shield flags JS-HideMe-J[Trj] there).
and here at http://jsunpack.jeek.org/?
See: http://maldb.com/www.dnps.com/
Missed here: https://www.virustotal.com/nl/url/88d27f1228f939f2b214a7a3375b4e70f68f9e1ddafc1f07c493878624540a76/analysis/
Server redirect status: Code: 301,  htxp://www.detroitmedia.com/   Redirect to external server!
JavaScript check: Suspicious
language="javascript">function dnnviewstate(){var a=0,m,v,t,z,x=new array("9091968376","8887918192818786347374918784939277359287883421333333338896","778787","949
Spam Check:
Suspicion of Spam
ef="htxp://safe-md-store.com">canadian **SPAM**</a></p><p class="dnn"><a href="htxp://safeorderonline.webs.com">zithroma...
See: http://app.webinspector.com/public/reports/19408678
blacklisted external link see: http://sitecheck.sucuri.net/results/cetrk.com/pages/scripts/0010/1857.js
See: http://zulu.zscaler.com/submission/show/05c25548bc3c4a1b1ff544279d17a877-1389483028  malicious 100/100
Malicious file: wXw.detroitmedia.com/wp-content/themes/2033/js/jquery.cycle.all.pack.js
Severity:    Malicious
Reason:    Detected known malicious content.
Details:    Threat detected according to previously retrieved information
File size[byte]:    12403
File type:    ASCII
MD5:    B1CF759A030EE15AC0796C700413BC10
Scan duration[sec]:    0.001000

index
Severity:    Suspicious
Reason:   Detected suspicious redirection to external web resources at HTTP level. [What's this?]
Details:    Detected HTTP redirection to htxp://www.detroitmedia.com/.
File size[byte]:    18446744073709551615
File type:    Unknown
MD5:    00000000000000000000000000000000
Scan duration[sec]:    0.001000

Last two were Qutera's Scanned File Analysis,

polonus
« Last Edit: January 12, 2014, 12:39:55 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!