Author Topic: Is this safe?  (Read 2440 times)

0 Members and 1 Guest are viewing this topic.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Is this safe?
« on: August 15, 2015, 10:23:12 AM »
hXXps://bancopostaimpresaonline.poste.it/bpiol/js/banner.js


Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: Is this safe?
« Reply #2 on: August 15, 2015, 10:43:31 AM »
Thanks Pondus, but would it be possible for Avast staff to take a closer look? if it is an obfuscated script with strange behaviors? It's on a banking web site.
EDIT: I've submitted a ticket too.
« Last Edit: August 15, 2015, 12:17:03 PM by 1234ava »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Is this safe?
« Reply #3 on: August 15, 2015, 01:26:29 PM »
Phishy patterns, could well be malware related!

Code landing at -http://lamviectrenmang.co advert campaign, see: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fbancopostaimpresaonline.poste.it%2Fbpiol%2Fjs%2Fbanner.js
Site is vulnerable to the Poodle attack!
Extensive server header info proliferation detected: IBM_HTTP_Server/6.1.0.25 Apache/2.0.47 Win32  exploitable by SSL Key Renegotation.
This external link is blocked by uMatrix: -http://webtrendslive.com/
Link not available:- http://mybank.alliance-leicester.co.uk/
This is an external spam link -> -myonlineaccounts2.abbeynational.co.uk*;client.uralsibbank.ru
Interesrting Array going to an exploit kit...TSPY_ZBOT.AUY infested website!
Report for detection!

polonus (volunteer website security analyst and website error hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Is this safe?
« Reply #4 on: August 15, 2015, 07:30:39 PM »

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: Is this safe?
« Reply #5 on: August 21, 2015, 12:36:56 PM »
Avast's response to my ticket:
"Our virus specialists have been working on the problem and they informed me that the script is clean and will remain undetected by Avast."