Author Topic: Malware domain already blocked by adblocker...  (Read 1293 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Malware domain already blocked by adblocker...
« on: August 20, 2015, 03:03:08 PM »
Avast detects: JS:ScriptXE-inf [Trj]
Trojans detected:
Object: -http://51shengyi.com/yp/web/?122/category-news.html
SHA1: 863f48dde56b338c800c6d93eec239633a86e813
Name: TrojWare.JS.Redirector.EBFE
Object: -http://www.51shengyi.com/data/config.js
SHA1: a0b5d08df87e9b8f0958412d265b3d98d1520f0d
Name: TrojWare.JS.Redirector.EBFE
Object: -http://www.51shengyi.com/images/js/jquery.min.js
SHA1: b0d1d475cbb678ad3d0bb7f2e3189d0c27a68bf9
Name: TrojWare.JS.Redirector.EBFE
Object: -http://www.51shengyi.com/images/js/jqModal.js
SHA1: 1b46de0946e17efd608fa19d6f08ae1360d6b544
Name: TrojWare.JS.Redirector.EBFE
Object:-http://www.51shengyi.com/images/js/Std_StranJF.Js
SHA1: fffcd0d0fc0b5799c689336b88fb3d60f06db00f
Name: TrojWare.JS.Redirector.EBFE
Object: -http://www.51shengyi.com/images/js/common.js
SHA1: 0ca733b4df14ff0c0d0b6904b6e586a69f80e09f
Name: TrojWare.JS.Redirector.EBFE
Object: -http://www.51shengyi.com/images/js/validator.js
SHA1: 0c89f54172824d905e5eb0c6e10ca4f52d89da5f
Name: TrojWare.JS.Redirector.EBFE
See: https://www.virustotal.com/nl/url/743eca52f45b1a38f934f19ebc5ba6d20e48ce1b5177a52bf3ccc9fed03a8014/analysis/1440075303/
23 malicious and 7 suspicious files: http://quttera.com/detailed_report/www.51shengyi.com
Known javascript malware. Details: http://labs.sucuri.net/db/malware/malware-entry-mwjs2368?v2
Read: http://stackoverflow.com/questions/22244180/struts-2-bug-gaining-root-access-to-server
Detected reference to malicious blacklisted domain wXw.51shengyi.com
Suspicious
Code: [Select]
[[\x73\x63\x72\x69\x70\x74]] 
polonus
« Last Edit: August 20, 2015, 03:05:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!