Author Topic: Is this site malware or no? and something weird happen  (Read 4010 times)

0 Members and 1 Guest are viewing this topic.

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Is this site malware or no? and something weird happen
« on: July 10, 2012, 03:44:24 AM »
I was looking up about a/c filter which way does the arrow go.. and i saw this link on bing
hxxp://besthomeairpurifier1.com/air-conditioner-filter-which-way-does-arrow-go.htm/ 
It opened notepad with something weird instead of loading.. got me thinking is the page malware? Do you all get the same results? its so weird why open it download a document without me telling it to and open it in notepad?  I'm running a scan of my pc with mbam and sas to make sure nothing happened.. Just saying its weird right?  Note: It did this in IE9
« Last Edit: July 10, 2012, 03:48:24 AM by Coolmario88 »
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: Is this site malware or no? and something weird happen
« Reply #1 on: July 10, 2012, 04:35:57 AM »
It does the same in Firefox and opera and other browsers i think.. it doesn't load a site.. in other browsers that isn't IE it asks if you want to download the file or not.. its not just the page it goes to its the site itself as well.. Scan came out clean.. but its still very weird
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Is this site malware or no? and something weird happen
« Reply #2 on: July 10, 2012, 08:24:31 AM »
Could have been through a recent WP hack, site has WordPress issues, see: http://sitecheck.sucuri.net/results/besthomeairpurifier1.com/air-conditioner-filter-which-way-does-arrow-go.htm/   Page Risk Index (heuristics)
Suspicious code returned ////1: ? ?? ]^^^^{  6  ;S   ( O ;?I e  ; # =;  ^^     R? I P$C^etc.////
I get a warning for XSS attack code,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Is this site malware or no? and something weird happen
« Reply #3 on: July 10, 2012, 04:35:37 PM »
Well you have to cleanse your browser history cache from this content, this is just some trojan html malware avast detects in your browser. Good we have avast there! Code is malicious and online scanners do not detect. Thanks for the heads-up,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Is this site malware or no? and something weird happen
« Reply #4 on: July 10, 2012, 04:56:01 PM »
It does the same in Firefox and opera and other browsers i think.. it doesn't load a site.. in other browsers that isn't IE it asks if you want to download the file or not.. its not just the page it goes to its the site itself as well.. Scan came out clean.. but its still very weird
Why would you go to the potentially malicious site at hand with in a different browser to see if you get infected..? ::)

Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: Is this site malware or no? and something weird happen
« Reply #5 on: July 10, 2012, 06:51:02 PM »
It does the same in Firefox and opera and other browsers i think.. it doesn't load a site.. in other browsers that isn't IE it asks if you want to download the file or not.. its not just the page it goes to its the site itself as well.. Scan came out clean.. but its still very weird
Why would you go to the potentially malicious site at hand with in a different browser to see if you get infected..? ::)
I went to the site to see um if well it auto downloads the weird file auto without me telling it to like it did in IE
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Is this site malware or no? and something weird happen
« Reply #6 on: July 10, 2012, 09:41:10 PM »
It does the same in Firefox and opera and other browsers i think.. it doesn't load a site.. in other browsers that isn't IE it asks if you want to download the file or not.. its not just the page it goes to its the site itself as well.. Scan came out clean.. but its still very weird
Why would you go to the potentially malicious site at hand with in a different browser to see if you get infected..? ::)
I went to the site to see um if well it auto downloads the weird file auto without me telling it to like it did in IE
So you'd risk the possibility of an exploit that wasn't executed successfully that runs the file in a different mode e.g executable? I wouldn't take risks like that.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Is this site malware or no? and something weird happen
« Reply #7 on: July 10, 2012, 10:35:39 PM »
The file was only detected when scanning the browser cache afterwards. The site's content can be examined only through third party scanners, malzilla with sandbox and with a special file-viewer also in secure settings (sandboxed, script blocking etc.). To experiment opening such a site in various common browsers is playing out a considerable risk, because malcode could escape the browser, could infect the OS, could interfere with the networksettings etc. etc.
As far as I can see now taking the browser history cache to the chest would be the most secure option, as this malware apparently goes under the detection radar so far. Never go to live malcode directly in one of the main website browsers.....that is playing with fire,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!