Author Topic: Many new instances of Adware.InstallCore.75 not detected...  (Read 2218 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Many new instances of Adware.InstallCore.75 not detected...
« on: December 18, 2012, 11:40:51 PM »
See: http://zulu.zscaler.com/submission/show/d34c1f0741c71f6cbb13379fa133aae1-1355869181
See: https://www.virustotal.com/file/69806bbe830f62ad2077cf13588ce074e927860adb235b02e25c7353b03fc029/analysis/
and
https://www.virustotal.com/url/76314dc7b12e32798ff900d89f02cc1449a90ce8b2a12c4cbbf02ba41a572013/analysis/1355869823/
DrWeb detects but gives the url scan as clean...https://www.virustotal.com/file/99909ff66efa64cf6e6c4a65c67fd19eb15cbd9de07f04fbe9158efb0a6d800a/analysis/1355869839/

Site uses real user monitoring with
Code: [Select]
var NREUMQ≈ NREUMQ||[];NREUMQ.push redirects to htxp://d28me8o1j6adyz.cloudfront dot net/1355825149/i  and live tracking monitoring script "htxp:")+'//api.mixpanel dot com/site_media/js/api/mixpanel.2.js

Is this site suspicious or bordering on malware, as sucuri finds nothing wrong there: http://sitecheck.sucuri.net/results/mozilla-firefox.todownload.com/  and VirusWatch flags this with many instances launched from and active on 23.23.130.85

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!