Author Topic: Only Fortinet's and Sucuri's SiteCheck to detect counter.yadro.ru/hit? malware?  (Read 1211 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
See: https://urlquery.net/report.php?id=1435234583610
and https://www.virustotal.com/en-gb/url/60a9d9c172046ce3b25ccde470c0775ac249e9f93a4b66069ca77909475d7a25/analysis/1435234959/
ISSUE DETECTED   DEFINITION   INFECTED URL
Website Malware   MW:HTA:7   htxp://vkontakte.ru/video_ext.php?oid=30880752 ( View Payload )
Website Malware   MW:HTA:7   htxp://vkontakte.ru/video_ext.php?oid='+videoId[1]+' ( View Payload )
Domain detected on spam or phishing campaigns. Details: http://sucuri.net/malware/entry/MW:HTA:7
This specific URL was identified in malicious campaigns to disseminate malware.
System Details:
Running on: Apache
Redirects to: /badbrowser.php  -> https://sites.google.com/site/vikontake/vhod
Powered by: PHP/3.15018
DrWeb's adult content/violence/social networks -> https://www.crunchbase.com/organization/vk

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!