Author Topic: URL: Card Stealer  (Read 1549 times)

0 Members and 1 Guest are viewing this topic.

Offline ChuckAZUSA

  • Newbie
  • *
  • Posts: 1
URL: Card Stealer
« on: February 13, 2024, 03:24:38 PM »
New here, so pardon me if i violate any of the norms.  When I open www.apptivo.com from multiple browsers, Avast warns me that it has blocked a threat from cloudfront.net (there is a long preface to that, which I'll omit for brevity's sake).  Avast says it was blocked because it is infected with URL: CardStealer.  I reported to Apptivo, who gave me what seems like nonsense, which was to clear my browser cache, then maybe that it was a false flag, but I'd feel better if i heard from other users that may have seen something similar with Apptivo.

« Last Edit: February 13, 2024, 03:28:31 PM by ChuckAZUSA »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: URL: Card Stealer
« Reply #1 on: February 13, 2024, 04:27:05 PM »
Website is down …. Why? Maybe detection was correct

https://downforeveryoneorjustme.com/apptivo.com?proto=http&www=1

No screenshot of website/could not be scanned/empty response
https://urlscan.io/result/2d0f23ba-b31c-4631-a91a-fec83d5c92ef/

« Last Edit: February 13, 2024, 04:29:41 PM by Pondus »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89645
  • No support PMs thanks
Re: URL: Card Stealer
« Reply #2 on: February 13, 2024, 05:52:52 PM »
New here, so pardon me if i violate any of the norms.  When I open wXw.apptivo.com from multiple browsers, Avast warns me that it has blocked a threat from cloudfront.net (there is a long preface to that, which I'll omit for brevity's sake).  Avast says it was blocked because it is infected with URL: CardStealer.  I reported to Apptivo, who gave me what seems like nonsense, which was to clear my browser cache, then maybe that it was a false flag, but I'd feel better if i heard from other users that may have seen something similar with Apptivo.

Please break active links to suspect sites to avoid accidental exposure, only post the domain-name or change the www or https to wXw or hXXpc to break the link (as I have in the quoted text).

This is a strange one, see the attached image of the alert window with the Detail option selected.

Strange in that is a redirect to a subdomain of cloudfront.net and the favicon.ico appears to be doing something that it shouldn't, e.g. not just displaying an icon.  Why is beyond me, but I'm always suspicious of the favicon.ico doing something other than display an image/icon.  This domain would appear to be looking like or portraying to be cloudflare a common

Whilst this isn't for the same sub.domain I think it is related as it appears that cloudfront.net is an Amazon Content Delivery network (CDN).
https://www.reddit.com/r/cybersecurity/comments/dsf43y/what_is_d31qbv1cthcecs_cloudfront_net/

That said as far as I'm concerned the favicon.ico should be doing nothing other than displaying a sites icon in the browser.  Anything else to me is suspect and against what the favicon.ico file should have in it.  A very long time ago this was a common means of delivering/running malware code when you opened a site.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #3 on: February 14, 2024, 01:36:34 AM »
I am also new here but have encountered the same warning from Avast today when bringing up the above website.  Could someone please confirm whether it is safe to log in (given the warning says that multiple threats have apparently been blocked by Avast), or is the website currently compromised and therefore I should steer clear.  I have no idea about this sort of thing....  Thanks!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89645
  • No support PMs thanks
Re: URL: Card Stealer
« Reply #4 on: February 14, 2024, 01:46:43 AM »
I am also new here but have encountered the same warning from Avast today when bringing up the above website.  Could someone please confirm whether it is safe to log in (given the warning says that multiple threats have apparently been blocked by Avast), or is the website currently compromised and therefore I should steer clear.  I have no idea about this sort of thing....  Thanks!

I don't think anyone here who responded (Avast Users) can advise you if it is safe to log into the site if it is causing the redirect to another unknown site.

You say "the warning says that multiple threats have apparently been blocked by by avast", if you have screenshots of these alerts/threats then attach them, information is king so they can be analysed.

- Attaching Images to your post - When you Click the Reply button it opens a text window for you to post your comment (reply or post).
Click the Preview button, that shows what you have input and expands it to include 'Attachments and other options'. Click that it further expands, here you can attach images, etc. at the bottom of your post.
See my attached image, click to expand.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #5 on: February 14, 2024, 02:09:22 AM »
Hi David,
Thank you for your quick reply.  Hopefully I have attached the info you asked for - the first screen shot is from the login page, the other 3 are from another random page from the Apptivo website that came up when I typed in 'Apptivo card stealer' into google.  Thought I would test another page (other than the login page) to see if it too had a threat, and as you can see, it had/has 3...!  ps I tried to upload all 4 images, but they are too large, so hopefully 2 have come through below.  Let me know if you would like me to post the other 2.

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #6 on: February 14, 2024, 02:10:56 AM »
Looks like I have to do them one by one...

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #7 on: February 14, 2024, 02:11:37 AM »
Third one...

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #8 on: February 14, 2024, 02:12:24 AM »
And the final one.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline design_ink

  • Newbie
  • *
  • Posts: 6
Re: URL: Card Stealer
« Reply #10 on: February 15, 2024, 02:24:56 AM »
FYI Apptivo thank me for reporting the issue initially then emailed me some hours later to say that 'our team has confirmed that the loading of cloudfront.net URLs on the site is secure.  We utilise AWS CDN for hosting our website images.'  I am waiting to hear back as to whether they mean that they believe the Avast alerts are false alerts, or whether they mean that their team have found and removed the malware.  I suspect they are suggesting that the Avast alerts are false/incorrect.  If that is the case, how do I know that is true and that the site is safe and secure to use?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: URL: Card Stealer
« Reply #11 on: February 15, 2024, 06:35:12 AM »
You can report this site to Avast Labs here:  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Please report back.
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814