Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Why conditional redirect not detected here?
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: Why conditional redirect not detected here? (Read 1123 times)
0 Members and 1 Guest are viewing this topic.
polonus
Avast Überevangelist
Probably Bot
Posts: 34054
malware fighter
Why conditional redirect not detected here?
«
on:
January 15, 2014, 12:27:05 AM »
See:
http://maldb.com/lienz.st/#
See:
https://www.virustotal.com/nl/url/3f8b8af2809c0afca4ef8b6d18f2064c43a5a0ca9160091cd09f2b4d015fdf1e/analysis/1389741171/
See code:
http://jsunpack.jeek.org/?report=6f4e89029aa77e72baa5e02f704ef435d5699752
ESET-NOD32 detects this malware as HTML/ScrInject.B.Gen
Others find the site as benign:
http://app.webinspector.com/public/reports/19474354
Well this is not exactly helping IP security there:
http://sameid.net/ip/217.196.150.201/
(127 sites on one and the same IP address!)
-> Netblock size has size 7 (risk) ->
http://urlquery.net/report.php?id=8814725
RedKit launched from other domains on same IP!
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 34054
malware fighter
Re: Why conditional redirect not detected here?
«
Reply #1 on:
January 15, 2014, 01:36:52 AM »
This detection could well be a false positive because of an older java exploit found, compare ->
https://java.net/projects/swinglabs/sources/svn/content/trunk/website/web/scripts/moo/prototype.lite.js?rev=340
a stripped version of prototype ->
choose source contents = בחר מקור תוכן מהרשימה ->
http://www.globes.co.il/shared/js/he/main4_home.aspx?encoding=utf-8
My verdict: a benign variation on prototype code,
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Why conditional redirect not detected here?