Author Topic: What unlnown malware resides on this site?  (Read 2931 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
What unlnown malware resides on this site?
« on: September 29, 2014, 05:53:31 PM »
See: https://www.virustotal.com/nl/url/fee6e62b0f10fbd1e53ef861780299a3ec9c7140409e69afd609893672c5c87a/analysis/1412005503/
ISSUE DETECTED           DEFINITION                   VULNERABLE HEADER
Outdated Joomla Found   Security Announcements   Joomla under 2.5.20 or 3.3
Again Quttera to detect 2 files here: http://quttera.com/detailed_report/scottbassguitars.co.uk
/g%c3%a4stebuch.html?start=10
Severity:   Malicious
Reason:   Detected reference to blacklisted domain
Details:   Detected reference to malicious blacklisted domain is.gd
File size[byte]:   25010

4 suspicious files:
File type:   HTML/g%c3%a4stebuch.html?start=20  -  /g%c3%a4stebuch.html?start=40 - /g%c3%a4stebuch.html
- /g%c3%a4stebuch.html
Page/File MD5:   22A2056AB71A8E0 Detected references to blacklisted domain83BA747655B1B70AA
Scan duration[sec]:   0.171000
/g%c3%a4stebuch.html?start=60
Severity:   Malicious
Reason:   Detected reference to blacklisted domain
Details:   Detected reference to malicious blacklisted domain is.gd
File size[byte]:   28197
File type:   HTML
Page/File MD5:   820D8B824D7C614E09150263D6D2A569
Scan duration[sec]:   0.133000

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37621
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: What unlnown malware resides on this site?
« Reply #2 on: September 29, 2014, 06:30:47 PM »
Hi Pondus,

This report woke them up:
Code: [Select]
scottbassguitars.co.uk.htm/ error
[not analyzed] scottbassguitars.co.uk.htm/
     status: (referer=http:/www.ask.com/web?q=puppies)failure: <urlopen error [Errno -2] Name or service not known>
But site is up and not being blocked - Joomla issue?

This is OK: http://linkeddata.informatik.hu-berlin.de/uridbg/index.php?url=http%3A%2F%2Fscottbassguitars.co.uk&useragentheader=&acceptheader=

and see: http://jsunpack.jeek.org/?report=57494c2ff73adf572fa89869287c6f68498f34b2

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!