Author Topic: infection  (Read 2165 times)

0 Members and 1 Guest are viewing this topic.

Offline mcmanus06

  • Newbie
  • *
  • Posts: 1
infection
« on: March 21, 2021, 04:53:33 PM »
over and over again all day i get from avast: "we have aborted the connection on zpreland.com because was infected with Script:SNH-gen[adw]."  any advice?
« Last Edit: March 21, 2021, 05:29:11 PM by mcmanus06 »

Offline r@vast

  • Avast team
  • Massive Poster
  • *
  • Posts: 2758
Re: infection
« Reply #1 on: March 22, 2021, 04:21:53 PM »
over and over again all day i get from avast: "we have aborted the connection on zpreland.com because was infected with Script:SNH-gen[adw]."  any advice?

Hi,

I could not reproduce it. Could you please provide a screenshot?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: infection
« Reply #2 on: March 22, 2021, 06:46:30 PM »
I couldn't replicate it either, I get a redirect to zpreland.com/feed/
and get a "Sorry, the page you are looking for could not be found." error
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: infection
« Reply #3 on: March 23, 2021, 02:10:50 PM »
Dutch hoster in Amsterdam does not repond for domains on IP 139.45.197.130
Re: https://www.shodan.io/host/139.45.197.130
See: https://www.virustotal.com/gui/domain/zpreland.com/details
Re another domain there: https://sitecheck.sucuri.net/results/sub.static.ptoahaistais.com
The code returned by -zpreland.com/feed
Quote
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx</center>
</body>
</html>

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
« Last Edit: March 23, 2021, 02:20:20 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!