Author Topic: SE visitor redirect via iFrame detected?  (Read 1594 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34057
  • malware fighter
SE visitor redirect via iFrame detected?
« on: August 23, 2015, 10:43:09 AM »
See: -https://www.virustotal.com/nl/url/b351a4e0925c4da2166a00d15ef4c70a48363393c986122539611cf7c8c99017/analysis/
with zero detection; & -http://quttera.com/detailed_report/kjsrefuge.com with zero detection,
Sucuri's: Unable to properly scan your site. Content not found.
content:
Code: [Select]
<html><head><title></title></head> <frameset rows="*" frameborder="no" border="0" framespacing="0"> <frame src="htxp://clcktrck.net/path/lp.php?trvid=10003&amp;trvx=3721aa50&amp;search=&lt;&lt;keyword&gt;&gt;&amp;smid=&lt;&lt;subid&gt;&gt;&amp;dom=&lt;&lt;domain&gt;&gt;" name="mainFrame"></frame> </frameset> </html>  specific Campaign with canpaign id. ->
-http://www.domxssscanner.com/scan?url=http%3A%2F%2Fclcktrck.net%2Fpath%2Flp.php%3Ftrvid%3D10003%26amp%3Btrvx%3D3721aa50%26amp%3Bsearch%3D%26lt%3B%26lt%3Bkeyword%26gt%3B%26gt%3B%26amp%3Bsmid%3D%26lt%3B%26lt%3Bsubid%26gt%3B%26gt%3B%26amp%3Bdom%3D%26lt%3B%26lt%3Bdomain%26gt%3B%26gt%3B%22+name%3D%22mainFrame
Yahoo weather API stuff link in code.
Also consider: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fclcktrck.net%2Fpath%2Fout.php%3Fsxid%3D8wc80443z1af%26g%3D1398
See:- http://urlquery.net/report.php?id=1440319065398
landing at -insanetrack.com (extreme tracking and mal-ads with adult content)
-> suspicious ans spam related: -https://www.mywot.com/en/scorecard/truburnplustrial.com?utm_source=addon&utm_content=rw-viewsc

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!