Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Known infection source - executable flagged, still only one to flag!
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: Known infection source - executable flagged, still only one to flag! (Read 1094 times)
0 Members and 1 Guest are viewing this topic.
polonus
Avast Überevangelist
Probably Bot
Posts: 34051
malware fighter
Known infection source - executable flagged, still only one to flag!
«
on:
January 23, 2019, 01:58:24 AM »
Detected: ET POLICY Executable served from Amazon S3
See:
https://urlquery.net/report/70a9a2bf-9869-49a0-ba0d-4157a94e5843
(IDS flags)
and
https://www.virustotal.com/#/domain/files.astrogemini.com
and
https://www.virustotal.com/#/url/613b1879b9ca747d68522f84b923205f2343d2052fc44e64911a78437a6592b2/detection
Nothing here:
https://sitecheck.sucuri.net/results/files.astrogemini.com
Reported for IP:
https://cymon.io/65.158.47.152
but now resolving to a Cogent address: -38.29.168.138
See:
https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=Zltse3MufHN0fV1ne21bblsuXl1t~enc
See the ever-changing IP addresses:
https://cymon.io/domain/files.astrogemini.com
polonus (volunteer website security analyst and website error-hunter)
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Known infection source - executable flagged, still only one to flag!