Author Topic: Cannot replicate results in browser?  (Read 1158 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cannot replicate results in browser?
« on: July 20, 2014, 05:29:26 PM »
Bitdefender and WOT flag as malicious.

See: http://linkeddata.informatik.hu-berlin.de/uridbg/index.php?url=http%3A%2F%2Fy1lux.4gwpa43.com%2F&useragentheader=&acceptheader=
Re: Up(nil):   unknown_html   ARIN   US   abuse at nobistech dot net   23.105.87.7    to 23.105.87.7   4gwpa43dot com   http://y1lux.4gwpa43.com/
Found in there: <dd><a href="httx://xuanhuakaifapiao.xxl3prm.com" target=_blank>̩���д����豸��Ʊ</a></dd>
<dd><a href="htxp://nanchongshidaikaifapiao.oomwfg6.com" target=_blank>���Ƹۿ��豸��Ʊ</a></dd>
<dd><a href="htxp://daikaiechengqufapiao.q63wl.eu" target=_blank>ͼľ�����п��豸��Ʊ</a></dd>
<dd><a href="htxp://nanchongshidaikaifapiao.oomwfg6.com" target=_blank>��Ȫ���豸��Ʊ</a></dd>
<dd><a href="htxp://daikaijiangyongxianfapiao.shjpm.eu" target=_blank>�����д����豸��Ʊ</a></dd>
<dd><a href="htxp://daikaijiangyongxianfapiao.qn1ns.eu" target=_blank>���ֿ��豸��Ʊ</a></dd>
<dd><a href="htxp://daikaixuchangfapiao.ds3uc.eu" target=_blank>��ݸ�п��豸��Ʊ</a></dd>
<dd><a href="htxp://daikaixinzhengfapiao.lkq5j.eu" target=_blank>�������豸��Ʊ</a></dd>
<dd><a href="htxp://huichengqukaifapiao.i06s54r.com" target=_blank>�����̽����豸��Ʊ</a></dd>
<dd><a href="htxp://daikaixishuixianfapiao.iowauvf.com" target=_blank>������ͬ���豸��Ʊ</a></dd>
<dd><a href="htxp://jilinkaifapiao.qxyje6d.com" target=_blank>�����������豸��Ʊ</a></dd>
<dd><a href="htxp://wuhukaifapiao.bq75d.eu" target=_blank>�����д����豸��Ʊ</a></dd>

Bitdefender FP?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Tondah

  • Avast team
  • Jr. Member
  • *
  • Posts: 52
Re: Cannot replicate results in browser?
« Reply #1 on: July 21, 2014, 10:05:06 AM »
hi polonus,
its not exactly malware, but i found some weird behavior.
for example there is link to picture "y1lux.4gwpa43.com/style/images/mmlist_line_v2.png" which is in fact html page.
i think this is enough to consider this page not secure.