Author Topic: Again a PHP based CMS website with outdated plug-ins PHISHING.  (Read 1147 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34052
  • malware fighter
Again a PHP based CMS website with outdated plug-ins PHISHING.
« on: October 30, 2018, 11:16:56 PM »
Re: https://urlquery.net/report/ab87ae57-ad09-43a9-b408-feefa9f94003

WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

wordpress-seo 8.4   latest release (9.0.3) Update required
https://yoa.st/1uj
contact-form-7 5.0.4   latest release (5.0.5) Update required
https://contactform7.com/
Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

Various security recommendations (hints): https://webhint.io/scanner/e4f7035a-824f-49ab-b31d-2bf2d5e5bd58

Externally linked host = -www.skarweb.nl

Loaded:
-https://stormvogel.eu/
GoogleSafe:
OK   Load:
887ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-includes/js/wp-emoji-release.min.js?ver=4.9.8
GoogleSafe:
OK   Load:
92ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.0.4
GoogleSafe:
OK   Load:
183ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/style.css?ver=4.9.8
GoogleSafe:
OK   Load:
273ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/bootstrap/bootstrap.css?ver=4.9.8
GoogleSafe:
OK   Load:
373ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/css/bootstrap-glyphicons.css?ver=4.9.8
GoogleSafe:
OK   Load:
282ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/css/animate.css?ver=4.9.8
GoogleSafe:
OK   Load:
279ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/css/prettyPhoto.css?ver=4.9.8
GoogleSafe:
OK   Load:
276ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/css/theme.css?ver=4.9.8
GoogleSafe:
OK   Load:
274ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/css/custom.php?ver=4.9.8
GoogleSafe:
OK   Load:
792ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-includes/js/jquery/jquery.js?ver=1.12.4
GoogleSafe:
OK   Load:
461ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
GoogleSafe:
OK   Load:
364ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=5.0.4
GoogleSafe:
OK   Load:
366ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/bootstrap/bootstrap.min.js?ver=20120206
GoogleSafe:
OK   Load:
366ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/jquery.superslides.js?ver=20120206
GoogleSafe:
OK   Load:
455ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/jquery.slides.min.js?ver=20120206
GoogleSafe:
OK   Load:
456ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/jquery.prettyPhoto.js?ver=20120206
GoogleSafe:
OK   Load:
457ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/navigation.js?ver=20120206
GoogleSafe:
OK   Load:
458ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/skip-link-focus-fix.js?ver=20130115
GoogleSafe:
OK   Load:
545ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-content/themes/Adament/js/custom.js?ver=20120206
GoogleSafe:
OK   Load:
545ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-https://stormvogel.eu/wp-includes/js/wp-embed.min.js?ver=4.9.8
GoogleSafe:
OK   Load:
547ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl
-http://fonts.googleapis.com/css?family=Cabin:400,500,600,700
GoogleSafe:
OK   Load:
31ms   Server: -216.58.217.74
ESF   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f74.1e100.net
-http://fonts.googleapis.com/css?family=Roboto+Condensed:400,700
GoogleSafe:
OK   Load:
46ms   Server: -216.58.217.74
ESF   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f74.1e100.net
-https://www.skarstats.nl/piwik.js
GoogleSafe:
OK   Load:
602ms   Server: -149.210.132.71
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-www.skarstats.nl
-http://fonts.gstatic.com/s/cabin/v12/u-4x0qWljRw-Pd8w__s.woff
GoogleSafe:
OK   Load:
24ms   Server: -216.58.217.67
sffe   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f3.1e100.net
-http://fonts.gstatic.com/s/cabin/v12/u-480qWljRw-PdfD3Ohluy8.woff
GoogleSafe:
OK   Load:
28ms   Server: -216.58.217.67
sffe   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f3.1e100.net
-http://fonts.gstatic.com/s/cabin/v12/u-480qWljRw-Pdfv2-hluy8.woff
GoogleSafe:
OK   Load:
30ms   Server: -216.58.217.67
sffe   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f3.1e100.net
-http://fonts.gstatic.com/s/cabin/v12/u-480qWljRw-PdeL2uhluy8.woff
GoogleSafe:
OK   Load:
34ms   Server: -216.58.217.67
sffe   ASN: 15169 United-States
Google LLC   Reverse DNS:
-iad23s41-in-f3.1e100.net
-https://stormvogel.eu/wp-content/themes/Adament/fonts/glyphiconshalflings-regular.woff
GoogleSafe:
OK   Load:
182ms   Server: -149.210.132.236
Apache/2   ASN: 20857 Netherlands
Transip B.V.   Reverse DNS:
-vps-s04.skarweb.nl

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!