Author Topic: What abuse is going on here -redirect malcode?  (Read 1106 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33976
  • malware fighter
What abuse is going on here -redirect malcode?
« on: March 18, 2015, 03:20:34 PM »
See: https://www.virustotal.com/en/url/4a56e4477546c71feeb8c528a585ba32c2c6bfd6dedd471d476092dac1c38f0c/analysis/1426687087/
2 suspicious files with Severity:   Suspicious
Reason:   Detected reference to blacklisted domain
Details:   Detected reference to suspicious blacklisted domain -counter.yadro.ru
HTTP Errors Returned -> http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fva-vadik.narod2.ru&useragent=Fetch+useragent&accept_encoding=
HTTP 503 view: https://www.uploady.com/download/tqhaNAR6WTe/4hKkKyCrp2mPV5Lx
404 error-check:
Suspicious

Suspicious 404 Page:
   -.ru/hit;counter1?r"+escape(document.referrer)+((typeof(screen)=="undefined")?"":";s"+screen.width+"*"+screen.height+"*"+
503 Service Unavailable Server Redirect /Status
The server is currently unavailable (because it is overloaded or down for maintenance). Generally, this is a temporary state.

Attached a tracker tracker report - do not open links in a browser as txt results are just for security research purposes.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!