Author Topic: Malware mw-redir-fakeav533 still on site?  (Read 1180 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33915
  • malware fighter
Malware mw-redir-fakeav533 still on site?
« on: December 18, 2013, 11:49:19 AM »
See: http://maldb.com/sa-safaris.com/
and also: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fsa-safaris.com
Nothing here: https://www.virustotal.com/nl/url/a5ebe675f8a79c450b9cf72eedb7bd88a68566a305ee5ebe7641043d9cb5ed2d/analysis/1387362981/
nor here: http://zulu.zscaler.com/submission/show/32021c18aaaa7852e6d028d750896f38-1387363364
Still reported as Phish.
Suspicious according to Quttera's: index
Severity:    Suspicious
Reason:   Detected suspicious redirection to external web resources at HTTP level.
Details:    Detected HTTP redirection to htxp://kasoas.ru/space?7.
File size[byte]:    4294967295
File type:    Unknown
MD5:    00000000000000000000000000000000
Scan duration[sec]:    0.001000

/mootools.js
Severity:    Potentially Suspicious
Reason:    Detected potentially suspicious content.
Details:   Detected potentially suspicious initialization of function pointer to JavaScript method write <code> __tmpvar650172348 = write; <code/>
Threat dump:   http://jsunpack.jeek.org/?report=3d683db3b73b7c401d1d3bef7a3a2c9ff37f3195
File size[byte]:    36644
File type:    ASCII
MD5:    17FF0A03FCFF2953A340425B72C318B4
Scan duration[sec]:    0.171000

polonus
« Last Edit: December 18, 2013, 11:52:42 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!