Author Topic: This anime streaming site ifected with/contains malware?  (Read 2499 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
This anime streaming site ifected with/contains malware?
« on: November 15, 2015, 12:16:56 PM »
Hi again! Another website I've used reguraily, used for streaming One Piece anime "watchop.cc" seems to contain some malicious content according to Sucuri. I've checked this website in Sucuri couple of times in the pas, but the notivication of malicious content seems to show up for the first time. Virustotal also shows two blacklists, one for malicious and other for suspicious.

https://sitecheck.sucuri.net/results/watchop.cc/

https://www.virustotal.com/en/url/7430faf2981f7fa746d48a97ee6ec55d0ab508011ef25d9db06e4cd751ef0f03/analysis/1447585806/

EDIT: these show up clean;

Quote
incected URL: -http://watchop.cc/manga/
Location: -http://watchop.in/manga2/

https://sitecheck.sucuri.net/results/watchop.cc/manga/
https://sitecheck.sucuri.net/results/watchop.in/manga2/
« Last Edit: November 15, 2015, 12:44:38 PM by Pernaman »


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: This anime streaming site ifected with/contains malware?
« Reply #2 on: November 15, 2015, 02:44:49 PM »
Hi Eddy and Pernaman,

It is more that your adblocker should work overtime there to block ad- and tracking servers. Like  uBlock₀ has prevented the following page from loading:
-http://de.tynt.com/
Because of the following filter
-||de.tynt.com^
Found in: hpHosts’ Ad and tracking servers
Also blocked for me: -http://cdn.cpmstar.com/cached/js/siteskin_v100.pack.js
and -http://cdn.cpmstar.com/cached/js/popunder_v101.pack.js
And uBlock₀ has prevented the following page from loading:
-http://t.dtscout.com/i/etc.
Because of the follwoing filter
-||t.dtscout.com^
Found in: hpHosts’ Ad and tracking servers • MVPS HOSTS
uBlock₀ has prevented the follwoing page from loading:
-http://i.simpli.fi/dpx.js?cid=21707&m=1&sifi_tuid=6329
because of the follwing filter
-||i.simpli.fi^
Found in: hpHosts’ Ad and tracking servers •
MVPS HOSTSuBlock₀ has prevented the follwoing page from loading:
-http://whos.amung.us/pingjs
because of the following filter
-||whos.amung.us^
Found in: hpHosts’ Ad and tracking servers •
MVPS HOSTSuBlock₀ has prevented the follwing page from loading:
-http://whos.amung.us/pingjs
Because of the following filter
-||whos.amung.us^
Found in: hpHosts’ Ad and tracking servers • MVPS HOSTS

So the website can be safely visited with a decent adblocker with the appropriate filterlist blocking (MVPS Host's block list installed). So content of the website is secondairy to ad serving and ad tracking commercialization, even to an extent it puts the visitors of that website at risk or may lead to adware related infections!

Flagged jquery - 2.1.1 : (active1) -http://watchop.cc/jquery.min.js
(active) - the library was also found to be active by running code -> http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwatchop.cc%2Fjquery.min.js (nginx on Debian run). Risk of Virus Profile: JS/IFrame.gen.j in
in vulnerable  jquery.flexslider.js via exploit.

polonus (volunteer website security analyst and website error hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!