Author Topic: Site with Troj/VB-EXA?  (Read 1537 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Site with Troj/VB-EXA?
« on: August 14, 2012, 01:50:51 AM »
See: http://urlquery.net/report.php?id=128564
scrpt source = htxp://d2.zedo.com/jsc/d2/fo.js with  suspicious code  from d2.zedo.com/jsc/d2/fo.js
XSS inscription injection detected: http://xss.cx/examples/dork/xss/3.22.2011.dork-xss-report.html
see: http://xss.cx/examples/dork/xss/3.22.2011.dork-xss-report.html#2.2
See http requests and DNS request in Sophos's Detailed Analysis: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~VB-EXA/detailed-analysis.aspx (also going to this request source)....FILEMAGIC Macromedia Flash data (compressed) on http://urlquery.net/report.php?id=96773

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!