Author Topic: Sucuri denied me to scan website....  (Read 1213 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Sucuri denied me to scan website....
« on: January 01, 2018, 11:05:32 PM »
See: https://urlquery.net/report/bce47fb0-0ee8-4526-aaf4-d22beaaad2fb
Detected PHISHing via Word Press theme.

Reason as Sucuri gives it:
Quote
URL: scan for: -sitecheck.sucuri.net/results/cbs-semenov.ru/wp-content/
Your Browser:   common webbrowser (third party cold reconnaissance scan on sucuri website blocked by their firewall -
Block ID:   DIR081
Block reason:   Directory listing denied.
This temporary block happens when our Intrusion Detection System (IDS) detects suspicious actions
and blocks a visitor's IP for a 30 minutes period.
N.B. Wonder whether  their IDS firewall alert is also that aggressive,
when the scan comes from or through Google's VT?

A general domain Sucuri scan cannot scan properly, only gives server version info proliferation:
Quote
Scan for: htxp://cbs-semenov.ru
Hostname: -cbs-semenov.ru
IP address: 5.101.152.140

System Details:
Running on: nginx-reuseport/1.13.4
Loaded resources: GoogleSafe:
OK   Load:
551ms   Server: -5.101.152.140
nginx-reuseport/1.13.4   ASN: 198610 Russia
Beget Ltd   Reverse DNS:
-m2.diffie.beget.ru

  error: undefined function location.reload sourcecode:
Quote
<html><head><script>function set_cookie(){var now = new Date();var time = now.getTime();time += 19360000 * 1000;now.setTime(time);document.cookie='beget=begetok'+'; expires='+now.toGMTString()+'; path=/';}set_cookie();location.reload();;</script></head><body></body></html>
Also get this as I bring up mazilla malware browser and excactly this...

So is the website being cleansed? No, but it is not like given above, according to: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=cbs-semenov.ru&ref_sel=GSP2&ua_sel=ff&fs=1

Compare to scan results and flags here: http://retire.insecurity.today/#!/scan/38ed7cbf465e92266995309835c77c054d333bca00733ffb28908c152a6e3157

polonus
« Last Edit: January 01, 2018, 11:19:51 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Re: Sucuri denied me to scan website....
« Reply #1 on: January 02, 2018, 12:45:45 AM »
The obvious reason for this can be concluded from the image on the urlquery scan.
This is what turned up green - 2 files: (mind the skew... ;)...
Quote
index.html
Severity:   Clean
Reason:   No significant issues detected.
Details:   File is clean
File size[byte]:   274
File type:   HTML
Page/File MD5:   DDE72AE232DC63298465861482D7BB93
Scan duration[sec]:   0.104
&
Quote
ndex.html
Severity:   Clean
Reason:   No significant issues detected.
Details:   File is clean
File size[byte]:   274
File type:   HTML
Page/File MD5:   DDE72AE232DC63298465861482D7BB93
Scan duration[sec]:   0.025


polonus
« Last Edit: January 02, 2018, 12:47:39 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!