Author Topic: What is wrong at this site? PHISH!  (Read 1687 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
What is wrong at this site? PHISH!
« on: August 25, 2015, 09:26:25 AM »
See: -https://www.virustotal.com/nl/url/a6c9bdc1e909879fe777837d01cd94c4d1f8f1c260c666bffc3b60622c3f7ab1/analysis/1440486616/
Blacklisted by Quttera Labs. Unable to properly scan your site. Unable to connect.
Phishing blacklisted, see: -http://urlquery.net/report.php?id=1440487326522
See: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.medisoluciones.com
WP: WordPress Version
3.8.5
Version does not appear to be latest 4.3 - update now.
WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

nextgen-gallery   latest release (2.1.7)
-http://www.nextgen-gallery.com
transposh-translation-filter-for-wordpress   latest release (0.9.6)
-http://transposh.org/
wordpress-seo   latest release (2.3.4)
-https://yoast.com/wordpress/plugins/seo/
contact-form-7   latest release (4.2.2)
-http://contactform7.com/

WordPress Theme
The theme has been found by examining the path /wp-content/themes/ *theme name* /

 Attitude 1.2.5http://themehorse.com/themes/attitude
Warning User Enumeration is possible
Warning Directory Indexing Enabled

Yoast WordPress SEO plugin v1.4.24 should be updated. -> blind-sql-injection-vulnerability

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: August 25, 2015, 09:30:01 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: What is wrong at this site? PHISH!
« Reply #1 on: August 25, 2015, 09:43:06 AM »
Another PHISH but in another manner. Detected?
See: -http://1col.ru/www.unr5.pfrally.com
See: miised here: -http://killmalware.com/unr5.pfrally.com/8wbgwb/fotoopv9ic2ie4jbhb9yi
See: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Funr5.pfrally.com%2F8WbgWb%2FfOTOopv9ic2ie4jbHb9Yi
Blacklisted: -http://urlquery.net/report.php?id=1440487939949
Malware reported: https://cymon.io/103.240.82.17

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!