Author Topic: Suspicious javascript detected?  (Read 2705 times)

0 Members and 1 Guest are viewing this topic.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34056
  • malware fighter
« Last Edit: March 23, 2014, 06:05:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
« Last Edit: March 23, 2014, 06:12:43 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34056
  • malware fighter
Re: Suspicious javascript detected?
« Reply #3 on: March 23, 2014, 06:24:11 PM »
Hi Steven Winderlich,

Better not venture out there: https://www.mywot.com/en/scorecard/mybogner.ru?utm_source=addon&utm_content=popup-donuts
I get an IDS alert there for "ET POLICY Maxmind geoip check to /app/geoip.js" -> http://urlquery.net/report.php?id=1395595008541
That means there is infection traffic spotted there, that is being used by a trojan.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Suspicious javascript detected?
« Reply #4 on: March 23, 2014, 06:30:10 PM »
No big Deal inside a virtual machine.

But i wonder why its not blocked by Avast?

Website is reported to Avast via Mail. :)
« Last Edit: March 23, 2014, 06:32:39 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34056
  • malware fighter
Re: Suspicious javascript detected?
« Reply #5 on: March 23, 2014, 07:06:41 PM »
Hi Steven Winderlich,

Because the main domain is online, but not that particular sub-domain: nitkiozz dot hotbox dot ru.htm
It's not just you! htxp://nitkiozz.hotbox.ru.htm looks down from here.
So if that is the situation, no longer online, how would avast! add detection then.
They were simply too late, the other 10 were in time to add protection.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Suspicious javascript detected?
« Reply #6 on: March 23, 2014, 07:08:22 PM »
I also send them the other website where i got redirected to. :)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10