Author Topic: This VT query won't resolve for me....what's wrong?  (Read 1434 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
This VT query won't resolve for me....what's wrong?
« on: February 11, 2017, 10:05:30 PM »
See: http://urlquery.net/report.php?id=1486828026307
Trying to do an url scan for this on Virus Total does not resolve, I only see connection to:
http://ghs-vip-any-c46.ghs-ssl.googlehosted.com/ (given as an error)
-> http://toolbar.netcraft.com/site_report?url=http://ghs-vip-any-c46.ghs-ssl.googlehosted.com
which is to virustotal base - http://www.virustotal.com.ipaddress.com/

Normal 200 status here: -https://aw-snap.info/file-viewer/?tgt=http%3A%2F%2Ftestirovshik.pp.ua%2F&ref_sel=GSP2&ua_sel=ff&fs=1  (to see unbreak link).
hxxp://counter.yadro.ru/hit?t44.1;r should be flagged there....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: This VT query won't resolve for me....what's wrong?
« Reply #1 on: February 11, 2017, 10:25:20 PM »
Must have been something with the cache, as later I could get here:
https://www.virustotal.com/nl/url/8742b4a257f059ddb2e487ee8bffb10d549da550590c22bbca90547fadfc6630/analysis/

Seems the name of the game here is adware! Also has outdated server software: Outdated Web Server Nginx Found   Vulnerabilities on nginx   nginx/1.2.1

Potentially suspicious code detected: /comments/script.js
Severity:   Potentially Suspicious
Reason:   Detected procedure that is commonly used in suspicious activity.
Details:   Too low entropy detected in string [['/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uf']] of length 106 which may point to obfuscation or shellcode.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!