Author Topic: Avast does not detect virus.html.gen03.26 aka PHISH.Stealer?  (Read 1474 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Avast does not detect virus.html.gen03.26 aka PHISH.Stealer?
« on: August 22, 2015, 12:07:32 PM »
See: https://www.virustotal.com/nl/url/81cfdd60e54b81e97b1e503edf62da30a43cc659e34f05f9911272fb843b76d4/analysis/1440237467/
and
https://www.virustotal.com/nl/file/6dde79e6b5e24455afdf1e01f1373d797e8ec2293bb25b54e9050b40cd71164c/analysis/1439286790/
Detected: http://zulu.zscaler.com/submission/show/6c43c45474e5a06cfef16b616eab5bab-1440237609
Outdated WordPress Found   Security Updates   WordPress Under 4.2
WP plug-ins issues:
WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

woocommerce 2.0.8   latest release (2.4.5) Update required
http://www.woothemes.com/woocommerce/
subscribe-to-download   
contact-form-plugin 3.17   latest release (3.93) Update required
http://bestwebsoft.com/products/
woodojo 1.5.0   
q-and-a 0.2.8   
easy-wordpress-donations   
contact-form-7 3.3.3   latest release (4.2.2) Update required
http://contactform7.com/
e-newsletter   
Quttera's  List of blacklisted external links: 90

Moreover main website bloched by Adguard.

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: August 22, 2015, 12:19:34 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: Avast does not detect virus.html.gen03.26 aka PHISH.Stealer?
« Reply #1 on: August 22, 2015, 12:15:40 PM »
Found here in  Results from scanning URL: -http://therespectalliance.org/wp-content/plugins/easy-wordpress-donations/includes/js/scripts.js?ver=3.5.2
Code: [Select]
  Document Ready Example 1
Code: [Select]
$(document).ready(function() {
    //do jQuery stuff when DOM is ready
});
Document Ready Example 2
Code: [Select]
$(function(){
//jQuery code here
});
  We detected example 2 there. Info credits go to Sam Deering.

Plug-in causing JS error: https://wordpress.org/support/topic/plugin-causes-js-error-which-breaks-admin-pages ->
/admin-scripts.js?ver=3.5.2

polonus
« Last Edit: August 22, 2015, 12:18:00 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!