Author Topic: Where Polonus again had to praise the blocking of the avast Network Shield  (Read 1599 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Stumbled upon this site and it was blocked by Google Safebrowsing. See: http://sitecheck.sucuri.net/results/deknipoog.kov.be
The suspicuious external; reference was:  htxp://veacce31ssedrev.rr.nu/sl.php?v=1  Avast Network Shield blocks this as URL:Mal
Giving this in as a search query in Google, this turned up many many infested websites, so there was an extensive malware campaign.
Seeking what IP to block there was, I found valid information here on Dynamoo's Blog: http://blog.dynamoo.com/2012/08/more-malware-sites-to-block-on.html
Quote
This says could save you a lot of grief
.... (quote taken from link article author = Conrad Longmore - UK)

From what I detected and from what I learned from entering the suspicious external referenced site in WebBug,
I say to all avast users: "You should have your avast Shields up under all circumstances!",

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
For suspicious link see: http://urlquery.net/report.php?id=133335
The URL host was subjected to threat Mal/HTMLGen-A.
source of it: http://www.ipillion.com/ip/91.196.216.176
IP had domain with Blackhole exploit kit: http://urlquery.net/report.php?id=46286
I get <!--InvalidServerName--> from that IP..

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!