Author Topic: Indicators of Compromise - misleading sites...e-mail compromittal of banksite.  (Read 964 times)

0 Members and 1 Guest are viewing this topic.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34052
  • malware fighter
See: -http://combicoat.nl/online/
-http://www.centerboden-aanrecht.nl/ has been closed for administrative reasons.
Dutch Banksite compromittal: https://otx.alienvault.com/pulse/5641cd3367db8c7a156b1a72/
See: http://toolbar.netcraft.com/site_report?url=%09www.centerboden-aanrecht.nl
Misleadiong site according to Google Safebrowsing alert: -http://combicoat.nl/online/ & -http://eopy.com/daSUs
See: http://toolbar.netcraft.com/site_report?url=htxp://combicoat.nl Suspended Domain
link bandito cannot be resolved: htxp://ow.ly/UrKJs
Outdated software detected at -https://www.orangelemon.nl/
HTTP Server: Apache HTTP Server 2 (Outdated)
PHP Version: 5.3.28 (Outdated)

-https://www.orangelemon.nl/
Detected libraries:
jquery - 1.4.4 : (active1) -https://www.orangelemon.nl/javascript/jquery.js
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery-ui-dialog - 1.8.5 : (active1) -https://www.orangelemon.nl/
(active) - the library was also found to be active by running code
1 vulnerable library detected Consider also: -http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.orangelemon.nl

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!