Author Topic: Malicious PHP content flagged here?  (Read 1117 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Malicious PHP content flagged here?
« on: August 22, 2015, 10:55:35 PM »
See:
-https://www.virustotal.com/nl/url/91dfc941e859e84a4a96024df4a321a8ce1991ac8b4beafbae2f7993157f6b73/analysis/1440275991/
index.html
Severity:   Malicious
Reason:   Detected malicious PHP content
Details:   Website Potentially DefacedSystem Details:
Running on: Apache/2.2.29
Powered by: PHP/5.4.39
Response: HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 19:03:23 GMT
Location: htxp://clancommission.us/D7
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 414
Content-Type: text/html; charset=iso-8859-1

Confirmed: -https://www.yandex.com/infected?url=clancommission.us&l10n=en&redircnt=1440276081.1
& -http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=clancommission.us

See: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.clancommission.us%2Fdownload.php%3Fview.28
adblockers will block: -https://e107.svn.sourceforge.net/svnroot/e107/trunk/e107_0.7/e107_files/e107.js

polonus

All links can be restored if one so wishes, but have been made non-click-through for obvious reasons,
as the posting is to add to or confirm existing Avast detection.

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!