Author Topic: Site with nocive flash installation  (Read 5019 times)

0 Members and 1 Guest are viewing this topic.

Henrique - RJ

  • Guest
Site with nocive flash installation
« on: May 07, 2013, 06:05:19 PM »
How to report site with malware ?

For virus[at]avast.com ?

Exist other way ?
« Last Edit: May 07, 2013, 06:43:35 PM by Henrique - RJ »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #1 on: May 07, 2013, 06:44:26 PM »
you can post the url here, but post it non clicable
http as hxxp and www as wxw

Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #2 on: May 07, 2013, 06:56:51 PM »
wxw.gamestorrents.com

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #3 on: May 07, 2013, 06:58:36 PM »

Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #4 on: May 07, 2013, 07:05:12 PM »
But why avast don't block it if possue hidden iframe ?

poor avast!
« Last Edit: May 07, 2013, 07:24:27 PM by Henrique - RJ »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #5 on: May 07, 2013, 07:07:56 PM »
But why avast don't block it if possue hidden iframe ?

poor avast!
no security program have 100% detection, and never will...... if they did there would not be a virus problem

Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #6 on: May 07, 2013, 07:09:32 PM »
And the false flash object update in the site ?
« Last Edit: May 07, 2013, 07:11:04 PM by Henrique - RJ »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #7 on: May 07, 2013, 07:24:26 PM »
the code displayed by sucuri is not detected by any one yet.... so can be very new, or not malicious

virustotal
https://www.virustotal.com/en-gb/file/8d3d5bcdf1b0bf4521d19b7aae8a8917b68329006432bf63d1da514c677ccb46/analysis/1367947228/

Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #8 on: May 07, 2013, 07:27:57 PM »
And this ?

wxw.telona.org/tarde-demais-dvdrip-xvid-dual-audio-rmvb-dublado/


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #9 on: May 07, 2013, 07:32:33 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #10 on: May 07, 2013, 07:34:39 PM »
And this ?

wxw.telona.org/tarde-demais-dvdrip-xvid-dual-audio-rmvb-dublado/

sucuri   http://sitecheck.sucuri.net/results/telona.org/tarde-demais-dvdrip-xvid-dual-audio-rmvb-dublado/

suspicious site...check it here  http://sucuri.net/


Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #11 on: May 07, 2013, 07:38:20 PM »
and the flash update is not a flash update.... it goes to this program

VirusTotal
https://www.virustotal.com/en-gb/file/9eb7823c11cabbe85676abf5be0320b3c8ca26452d210590c439609df1a2f086/analysis/1367947824/

Yes, this a virus but any one detect it yet.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Site with nocive flash installation
« Reply #12 on: May 07, 2013, 08:16:35 PM »
and the flash update is not a flash update.... it goes to this program

VirusTotal
https://www.virustotal.com/en-gb/file/9eb7823c11cabbe85676abf5be0320b3c8ca26452d210590c439609df1a2f086/analysis/1367947824/

Yes, this a virus but any one detect it yet.

Sigcheck

publisher................: Systweak Inc
product..................: RegClean Pro
copyright................: (c) Systweak Inc
file version.............: RegClean Pro
signing date.............: 12:43 PM 3/19/2013
comments.................: This installation was built with Inno Setup.
signers..................: Systweak Software; VeriSign Class 3 Code Signing 2010 CA; VeriSign Class 3 Public Primary Certification Authority - G5
description..............: RegClean Pro


Henrique - RJ

  • Guest
Re: Site with nocive flash installation
« Reply #13 on: May 07, 2013, 08:21:08 PM »
and the flash update is not a flash update.... it goes to this program

VirusTotal
https://www.virustotal.com/en-gb/file/9eb7823c11cabbe85676abf5be0320b3c8ca26452d210590c439609df1a2f086/analysis/1367947824/

Yes, this a virus but any one detect it yet.

Sigcheck

publisher................: Systweak Inc
product..................: RegClean Pro
copyright................: (c) Systweak Inc
file version.............: RegClean Pro
signing date.............: 12:43 PM 3/19/2013
comments.................: This installation was built with Inno Setup.
signers..................: Systweak Software; VeriSign Class 3 Code Signing 2010 CA; VeriSign Class 3 Public Primary Certification Authority - G5
description..............: RegClean Pro



??

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Site with nocive flash installation
« Reply #14 on: May 07, 2013, 11:04:16 PM »
Hi all,

Sucuri detected the iframe because it was a hidden iframe leading to an external source, not because of its content.

Although there is indeed a hidden iframe present, there is still the possibility of this iframe not containing malicious content.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."