Author Topic: What is HTML/Rce.Gen3 detection here?  (Read 1354 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33939
  • malware fighter
What is HTML/Rce.Gen3 detection here?
« on: August 07, 2015, 09:43:58 PM »
See: https://www.virustotal.com/nl/url/17a1f0dff2a44d41441c6308cbfbcd825dcac873a976a6c45c3da8ec941dd3cd/analysis/1438973596/
See:
Unable to properly scan your site. Website errors. Hacked: http://www.zone-h.org/mirror/id/24683942?zh=1
uMatrix blocked for me: http://www.easycounter.com/report/univ-mascara.dz
Listed: http://www.tcpiputils.com/browse/ip-address/193.194.87.74
http://toolbar.netcraft.com/site_report?url=http://dnserver.univ-mascara.dz
Fail here: http://www.dnsinspect.com/univ-mascara.dz/1438976015
No complaints recorded: http://ip-address-lookup-v4.com/ip/193.194.87.74
See Netcraft Web Address Risk Status 1 red out of 10: http://toolbar.netcraft.com/site_report?url=http://193.194.87.74
Webserver exploits for Apache-AdvancedExtranetServer/1.3.26 Mandrake Linux/6mdk mod_ssl/2.8.10 OpenSSL/0.9.6g PHP/4.2.3  (excessive webserver version info proliferation detected).
http://www.securityfocus.com/archive/1/369409/2004-07-17/2004-07-23/0
-> -http://www.arn.dz/ -> http://toolbar.netcraft.com/site_report?url=http://www.arn.dz
Possible Frontend SPOF from:

ajax.googleapis.com - Whitelist
(94%) - <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js" type="text/javascript">
vuln.: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.arn.dz%2F

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37626
  • Not a avast user
Re: What is HTML/Rce.Gen3 detection here?
« Reply #1 on: August 07, 2015, 10:05:33 PM »
Quote
Unable to properly scan your site..............
that often mean this   ;)   http://downforeveryoneorjustme.com/http://dnserver.univ-mascara.dz/


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33939
  • malware fighter
Re: What is HTML/Rce.Gen3 detection here?
« Reply #2 on: August 07, 2015, 10:10:28 PM »
Or it was being sinkholed...what actually comes down to virtually the same - down...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!