Author Topic: What resides here?  (Read 1443 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
What resides here?
« on: September 17, 2015, 10:06:51 PM »
Re: https://www.virustotal.com/nl/url/890771f58d16b688a73ae7dba23a6f6335c8a4e31fb9c11611456cba079607ac/analysis/1442507472/
Scripts:
//use.typekit.net/abh7nvo.js
-https://cdn.zeltser.com/wp-includes/js/jquery/jquery.js
-https://cdn.zeltser.com/wp-includes/js/jquery/jquery-migrate.min.js
-https://cdn.zeltser.com/wp-content/themes/zeltser/library/js/libs/modernizr.custom.min.js
-https://cdn.zeltser.com/wp-includes/js/mediaelement/mediaelement-and-player.min.js
-https://cdn.zeltser.com/wp-includes/js/mediaelement/wp-mediaelement.js
-https://cdn.zeltser.com/wp-content/themes/zeltser/library/js/scripts.js
-https://cdn.zeltser.com/wp-includes/js/comment-reply.min.js

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: What resides here?
« Reply #1 on: September 17, 2015, 10:40:39 PM »
Quote
What resides here?
Nothing dangerous   

you should visit it, i think you will find it interesting    ;)

https://cdn.zeltser.com
https://zeltser.com/remnux-v6-release-for-malware-analysis/



« Last Edit: September 17, 2015, 10:48:02 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: What resides here?
« Reply #2 on: September 17, 2015, 11:04:59 PM »
But I ask this because I find this on VirusWatch Archives to-day: Up(nil):   unknown_html   ARIN   US   abuse at digitalocean.com   104.236.236.73    to 104.236.236.73   zeltser.com   https://zeltser.com/remnux-v6-release-for-malware-analysis/
So then I started looking, but could not find it right away.
Seems OK: http://toolbar.netcraft.com/site_report?url=https://zeltser.com
CRDF flags on VT. See: http://www.dnszilla.com/zeltser.com
Seems OK: https://www.robtex.net/#!dns=104.236.236.73

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!