Author Topic: What was this probe for? Avast one of the few to detect!  (Read 1710 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
What was this probe for? Avast one of the few to detect!
« on: April 10, 2013, 06:03:46 PM »
See: http://aw-snap.info/file-viewer/?tgt=http%3A%2F%2Fwww.yourirish.com%2Fxmlrpc.php&ref_sel=Google&ua_sel=ff
Nothing here: http://urlquery.net/report.php?id=1915066
Once flagged here: http://www.urlvoid.com/scan/yourirish.com/
See: http://www.websecurityguard.com/detail.aspx?domain=yourirish.com&url=yourirish.com
Conditional request? -> the location line in the header above has redirected the request to: hxtp://www.yourirish.com/
Active and up  HTML:Script-inf malcode from 2013-04-10 00:33:01      
Avast is one of the very few to detect: https://www.virustotal.com/en/file/0f15de3d201e364441524032ac4937e2034081e2a9aefe029174e4cef7bdd427/analysis/
Saved evidence: http://support.clean-mx.de/clean-mx/view_evidence?id=10021340&table=viruses (for security analysts only)
partial Wordpress version from source: 3.5.1 needs updating...
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: What was this probe for? Avast one of the few to detect!
« Reply #1 on: April 10, 2013, 06:33:01 PM »
Probably this was flagged as given on urlquery dot com: http://urlquery.net/report.php?id=1901237
Site migrated to another IP! Nothing being hosted there now: http://whatisonip.com/ip-address/199.59.150.7
to http://whatisonip.com/ip-address/96.8.127.233
See: http://sitevet.com/db/asn/AS36352
IDS flags for ssp_ssl: Invalid Client HELLO after Server HELLO Detected  SOURCE IP = outgoing NAT address
Nothing being detected here: http://zulu.zscaler.com/submission/show/d5607d45f88866984fcf07f0ca7bcb92-1365612049

polonus
« Last Edit: April 10, 2013, 06:54:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!