Author Topic: Malware threat pop ups from cnc.cedexis.com  (Read 2269 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Malware threat pop ups from cnc.cedexis.com
« on: March 25, 2017, 06:07:15 PM »
Hello everyone!

I have my antivirus keep popping up a message about threat from rpt.cedexis.com every time I open new window in google chrome.

Can someone advise please?

Thank you! :(

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76029
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Malware threat pop ups from cnc.cedexis.com
« Reply #1 on: March 25, 2017, 06:08:36 PM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: Malware threat pop ups from cnc.cedexis.com
« Reply #2 on: March 25, 2017, 09:56:45 PM »
The IP is flagged for port scanning, so Google Cloud/GoDaddy abuse: https://www.abuseipdb.com/check/107.178.243.85
Not flagged here: https://www.virustotal.com/en/ip-address/107.178.243.85/information/
Only content now returned = 1:  // Cedexis Inc.  javascript linking to -http://orbita-Lviv.com/media/jui/js/jquery.min.js etc.
-> http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Frpt.cedexis.com

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!