Author Topic: muddy-art-95d0 Analysis Requested  (Read 1301 times)

0 Members and 1 Guest are viewing this topic.

Offline KDibble

  • Sr. Member
  • ****
  • Posts: 229
muddy-art-95d0 Analysis Requested
« on: July 12, 2023, 05:30:27 PM »
Over the last few days three workstations running Avast Business Pro have alerted on this, as URL-Blacklist:

https://www.virustotal.com/gui/url/50462e8d4a7db80323a6fd6b2dae81baffe8643779c76003d86ded90235b7d71

This is a subdomain of workers.dev, according to Subdomain Finder.

The only thing in common among those three workstations is access to a group email account--but every other workstation here (nearly 100 of them) also has access to that account and they have not alerted.

I looked at one of the workstations. User reported seeing the alert while using a map website, either Google Maps or MapQuest. Browser (Firefox) history indicates extensive use of Google Maps but does not list the above-reported URL.

Avast is blocking this successfully but I'd like to know more about how this thing works. How does the browser hit that URL without logging it into History?

Thanks for any help.

Avast Business Pro
On-Premises Console 7.29.968
Endpoint program 23.5.2755
Definitions 230711-4

Offline KDibble

  • Sr. Member
  • ****
  • Posts: 229
Re: muddy-art-95d0 Analysis Requested
« Reply #1 on: July 12, 2023, 07:22:59 PM »
Updated:

Same user encountered this again at "MapAssist". Screenshot attached.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: muddy-art-95d0 Analysis Requested
« Reply #2 on: July 12, 2023, 08:14:17 PM »
Imp.gif = my guess a ad that is blocked on the website they access


Offline KDibble

  • Sr. Member
  • ****
  • Posts: 229
Re: muddy-art-95d0 Analysis Requested
« Reply #3 on: July 14, 2023, 05:56:19 PM »
Thank you!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: muddy-art-95d0 Analysis Requested
« Reply #4 on: July 15, 2023, 02:35:23 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!