Author Topic: Malicious site redirect?  (Read 1510 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Malicious site redirect?
« on: January 17, 2014, 11:39:02 PM »
A malcious site redirect or a vulnerable site redirect?
See: http://maldb.com/diamonddance-productions.com/#
and outdated Joomla! flagged here: http://sitecheck.sucuri.net/results/diamonddance-productions.com

Minimal detection: https://www.virustotal.com/nl/url/be279433fb0884d4851e83eb2669bf3b530484fa77f3976a5758acb064b5847e/analysis/
No alerts here: http://urlquery.net/report.php?id=8868932
redirect to  htxp://www.bolltec.com/media/jce/mediaplayer/license.php not available because of robot.txt (part of some malware campaign ->
malware IP: http://urlquery.net/report.php?id=8868963 -> http://evuln.com/tools/malware-scanner/diamonddance-productions.com/

Inclusion Check:
Suspect - please check list for unknown includes

htxp://diamonddance-productions.com/plugins/system/yoo_effects/yoo_effects.js.php?lb=1&re=1&sl=1 -> uncaught exception: Unable to load Shadowbox, MooTools library not found -> http://jsunpack.jeek.org/?report=ef0868ad6c16d1da6e8e387ca164d9456ee0543c
Suspicious Filename Character score + low risk XSS vulnerability in YJ Whois Joomla versions 1.0x and 1.5.x.

polonus
« Last Edit: January 17, 2014, 11:46:45 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Malicious site redirect?
« Reply #1 on: January 18, 2014, 12:54:40 AM »
YOuch!
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.