Author Topic: SE visitors redirect flagged by avast?  (Read 18066 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
SE visitors redirect flagged by avast?
« on: March 22, 2014, 12:41:02 AM »
See: http://killmalware.com/writemymortgage.com/#
SE visitors redirects
Visitors from search engines are redirected
to: htxp://redoperabwo dot ru
redoperabwo dot ru is reported by Google as suspicious
1243 sites infected with redirects to this URL

See: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fwritemymortgage.com%2F
WordPress version outdated: Upgrade required.
Suspicious domain detected: http://sucuri.net/malware/malware-entry-mwblacklisted35

Javascript check suspicious: uspicious

rm" action="htxp://redoperabwo dot ru/parking.php" method="get" name="searchform"><fieldset><input type="hidden" name="ses" value="y3jlptezotu0ndq5njgmdgnpzd1yzwrvcgvyywj3by5ydtuzmmnjy...

404-error check: Suspicious 404 Page:
   .ru/parking.php" method="get" name="searchform"><fieldset><input type="hidden" name="ses" value="y3jlptezotu0ndq5njkmdgn

External links to: htxp://www.sedo.com/services/parking.php3
because virus tracker classification: writemymortgage dot com,192.254.234.8,ns6495.hostgator dot com,Parked/expired,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #1 on: March 23, 2014, 12:50:15 AM »
This one is not flagged: http://killmalware.com/schultzerbse.de/#
SE visitors redirects
Visitors from search engines are redirected
to: htxp://itsme.eu/
5 sites infected with redirects to this URL
Not flagged here: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fschultzerbse.de
-> http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fschultzerbse.de%2F&useragent=Fetch+useragent&accept_encoding=

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #3 on: March 23, 2014, 07:30:35 PM »
Here we can detect how that SE visitors redirect was wrought - via uploaded Joomla backdoor * all PHP files were infested/
Visitors from search engines are redirected
to: hxtp://www.stlp.4pu.com/
7342 sites infected with redirects to this URL

* http://ninjafirewall.com/malware/index.php?threat=2012-08-24.03

Web Rep: http://www.webutations.org/go/review/stlp.4pu.com

Re: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fpavementrestore.org%2F
Site with malware: http://sucuri.net/malware/entry/MW:SPAM:SEO & http://sucuri.net/malware/malware-entry-mwspamseom/js/caption.js
Joomla Version 1.5.18 - 1.5.26 for: http://pavementrestore.org//media/syste
Joomla Version 1.5.18 to 1.5.26 for: http://pavementrestore.org//language/en-GB/en-GB.ini
Joomla version outdated: Upgrade required.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast? TESTED
« Reply #4 on: March 23, 2014, 11:40:29 PM »
See SE redirect here: http://killmalware.com/millennium-international.net/#
Is not SE friendly as checked against this : http://www.webconfs.com/redirect-check.php
Either hxtp://millennium-international.net/ is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY
and the destination: Either htxp://tonycar.com/css/4.php is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #5 on: March 24, 2014, 07:41:36 PM »
See how the use of this Backlink Checker can help your evaluation of a particular SE redirect.
See: http://killmalware.com/uscoptic.com/#
See: http://smallseotools.com/backlink-checker/
See how WOT, Quttera and McAfee's Site Advisor treats the redirect site: Total backlinks: 178   
Example: https://www.mywot.com/en/scorecard/medicsph.ru
Strongly advise to use this for evaluation purposes (use inside a VM or sandbox please),
as we even learn that site is down now: http://www.statscrop.com/www/medicsph.ru  (backlink on page 2)

pol
« Last Edit: March 24, 2014, 07:53:30 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #6 on: March 24, 2014, 11:53:31 PM »
See: http://maldb.com/northlinkva.com/#
Conditional redirects found. Visitors from search engines are redirected
to: htxp://canadianonlinedrugs dot com/
Redirect to this URL found in 9 sites

Via Backlink Checker found this report: http://scamfraudalert.org/2014/01/06/bestpricedrugs24-org/
WOT is somewhat milder in it's web rep report: https://www.mywot.com/en/scorecard/bestpricedrugs24.org?utm_source=addon&utm_content=popup-donuts

See for this Russian based redirect: http://toolbar.netcraft.com/site_report?url=http://bestpricedrugs24.org
Site not malicious an sich. Most malware from IP being closed also from mentioned site:
http://support.clean-mx.de/clean-mx/viruses.php?email=noc@arpnetworks.com&response=

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #7 on: March 26, 2014, 12:48:45 AM »
This conditional SE redirect isn't malicious, is it?
See: http://killmalware.com/toy4kid.ru/#
SE visitors redirects
Visitors from search engines are redirected
to: htxp://ifyoucan.ru/miss.php?r=toy4kid.ru/&p=
180 sites infected with redirects to this URL
For: htxp://toy4kid.ru/ Found redirect to htxp://grame.ru/honda.php. The Redirect is Search Engine Friendly.
Either htxp://ifyoucan.ru/miss.php?r=toy4kid.ru/&p= is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY
Bitdefender TrafficLight blocks: http://www.urlvoid.com/scan/ifyoucan.ru/
badness history on IP: https://www.virustotal.com/nl/ip-address/78.110.50.117/information/

polonus

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #8 on: March 26, 2014, 03:20:06 PM »
See: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Frefuge7laux.fr
Suspicious conditional redirect.
Details: http://sucuri.net/malware/entry/MW:HTA:7
Redirects users to:htxp://miamiheattickets.com/http.php
Either hxtp://miamiheattickets.com/http.php is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY
Site has Namo WebEditor v5.0 Remote File Uploader, vulnerable to upload of PhP Shells via -> inurl:/module/upload_image/
Also consider: http://evuln.com/tools/malware-scanner/miamiheattickets.com/

Content that was returned by your request for the URL: htxp://refuge7laux.fr/tarifs-refuge-7laux.php
Note: Content displayed is from the redirect location, the URL htxp://miamiheattickets.com/http.php
Additionally, a 404 Not Found
8:error was encountered while trying to use an ErrorDocument to handle the request.

Additional for the nameserver: http://knujon.com/nameservers/NS61.1AND1.FR.html  (spam domain servers)

polonus
« Last Edit: March 26, 2014, 03:52:44 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #9 on: March 27, 2014, 04:22:34 PM »
See: http://urlquery.net/report.php?id=1395932925136
See: http://killmalware.com/eplantern.com/#http://evuln.com/labs/pityhandsdown.ru/

Nothing here: http://zulu.zscaler.com/submission/show/03ad865f2236a88bd04daf3856a52280-1395932833

Backlink info: http://www.runfo.ru/r/REGRU-REG-RIPN/286.htmlhttp://labs.sucuri.net/?malware&entry=2012-09-16
-> http://www.domaintuno.com/d/eplantern.com
Either htxp://pityhandsdown.ru/pavilion?8 is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY
Either htxp://eplantern.com/ is NOT REDIRECTING to any URL or the redirect is NOT SEARCH ENGINE FRIENDLY

Why site needs this affirmation of security? -> http://www.scamadviser.com/is-eplantern.com-a-fake-site.html

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #10 on: March 31, 2014, 07:11:42 PM »
See: http://killmalware.com/almansoor.com/#
Cannot connect -> http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Falmansoor.com
Source is clear here:
Code: [Select]
<font style='position: absolute;overflow: hidden;height: 0;width: 0'><a href="htxp://canadian-**SPAM**-center dot com">canadian online **SPAM**</a></font> htxp://canadian-**SPAM**-center.com/  not flagged
Redirection given was terminated because of violation of use by:
htxp://tinyurl.com/nospam.php?id=bp5bg4v
Quote
  The TinyURL (bp5bg4v) you visited was used by its creator in violation of our terms of use. TinyURL has a strict no abuse policy and we apologize for the intrusion this user has caused you. Such violations of our terms of use include:

Spam - Unsolicited Bulk E-mail
Fraud or Money Making scams
Malware
or any other use that is illegal.
If you received spam, please note that TinyURL did not send this spam and we do not operate any email lists. We can not remove you from spammer's database as we have no association with spammers, but instead we recommend you use spam filtering software. 
*

SE visitors redirects
Visitors from search engines are redirected
to: hxtp://tinyurl.com/bp5bg4v *
1097 sites infected with redirects to this URL (now as we know terminated because of abuse).

On IP we also saw a dead PHISH flagged: http://support.clean-mx.de/clean-mx/phishing.php?id=3978548

pol
« Last Edit: March 31, 2014, 07:14:04 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #11 on: March 31, 2014, 07:35:28 PM »
Following site with SE redirects has vulnerable CMS: Web application version:
Joomla Version: 2.5.6
Joomla Version 2.5.x - 3.0.x for: htxp://www.uboncloud.com/media/system/js/caption.js
Joomla Version 2.5.x for: htxp://www.uboncloud.com/language/en-GB/en-GB.ini
Joomla version outdated: Upgrade required.
SE visitors redirects
Chain of redirects found:
to: htxp://thecialispill.com
6 sites infected with redirects to this URL
See: https://www.mywot.com/en/scorecard/thecialispill.com?utm_source=addon&utm_content=rw-viewsc
to: htxp://pickupdrugstore.com/
7 sites infected with redirects to this URL  server redirect detected by Web Security Test: Code: 301,  htxp://pickupdrugstore.com/
Redirect to external server!  -> https://www.mywot.com/en/scorecard/pickupdrugstore.com?utm_source=addon&utm_content=rw-viewsc
avast flags this redirect site as infested with IRL;Mal

Security warnings, see: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fwww.uboncloud.com

Known Spam:SEO -> http://labs.sucuri.net/db/malware/malware-entry-mwspamseo

Missed completely here: http://zulu.zscaler.com/submission/show/9c9cf6e1356b6e57a586e1f66a4e0c9d-1396287019

So anayway from the redirect we are being protected by the avast! Webshield.

Read on that general brand of spam scam: http://spamtrackers.eu/wiki/index.php/Canadian_Family_Pharmacy

polonus
« Last Edit: March 31, 2014, 07:38:08 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #12 on: April 01, 2014, 11:46:10 PM »
Zscaler misses the conditional redirect here: http://zulu.zscaler.com/submission/show/eca6f4a4e763c39f0a6c2db930b2d46b-1396387424
But sucuri gives the warning: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fxn--k5caa.com%2F
and http://sucuri.net/malware/entry/MW:HTA:7
See: http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fxn--k5caa.com%2F&useragent=Fetch+useragent&accept_encoding=
Quttera also flags the suspicious redirect: index
Severity:    Suspicious
Reason:   Detected suspicious redirection to external web resources at HTTP level.
Details:    Detected HTTP redirection to htxp://dietprescriptioninc.net/.  About that campaign: http://evuln.com/labs/dietprescriptioninc.net/
-> http://domain-kb.com/www/dietprescriptioninc.net 
DNS check - errors and warnings: http://dnscheck.pingdom.com/?domain=dietprescriptioninc.net+&timestamp=1396388156&view=1
File size[byte]:    18446744073709551615
File type:    Unknown

Malware history for IP: http://support.clean-mx.de/clean-mx/viruses.php?ip=46.235.44.82&sort=id%20desc
Nothing here: http://urlquery.net/report.php?id=1396388315497
MD5:    00000000000000000000000000000000
Scan duration[sec]:    0.001000

kraken's Virus Tracker comes up with the following status: xn--k5caa dot com,46.235.44.82,ns3.webreus dot nl,Criminals,
this means that site has active malware up.
Hoster webreus dot nl had malware infections recently and server abuse:
http://webwereld.nl/datacenter/54341-sidn-roept-hoster-webreus-op-het-matje (link article author - webwereld editors)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #13 on: April 02, 2014, 06:36:06 PM »
See: http://killmalware.com/ovmpcllc.org/#
Unable to properly scan your site. Site empty (no content).
SE visitors redirects
Visitors from search engines are redirected
to: htxp://pkjlapok.1dumb.com/
1227 sites infected with redirects to this URL
->  http://labs.sucuri.net/db/malware/malware-entry-mwblacklisted35
No IP address found for the domain 'htxp://pkjlapok.1dumb.com'  Very poor webrep: https://www.mywot.com/en/scorecard/pkjlapok.1dumb.com
(no DNS answer).
Virus Tracker classifies as with live up active malware: ovmpcllc dot org,65.254.248.197,ns1.fatcow dot com,Criminals,

Not very reassuring result: http://sameid.net/ip/65.254.248.197/ -> http://urlquery.net/report.php?id=1396456207187

Badness history of IP: https://www.virustotal.com/nl/ip-address/65.254.248.197/information/

See reply by Jan Dembrowski here: http://wordpress.org/support/topic/google-doesnt-redirect-my-sites-error-message-server-not-found-pkjlapok1dumb

For malcode see: http://pastebin.com/hSWF0s1q

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SE visitors redirect flagged by avast?
« Reply #14 on: April 02, 2014, 10:24:31 PM »
This site with redirects is a vulnerable asp.net site: https://asafaweb.com/Scan?Url=truckinkrazy.com  error and warnings!
see: http://maldb.com/truckinkrazy.com/#
This time Zscaler scanner seems to be aware something is not right there: http://zulu.zscaler.com/submission/show/4d3d552ca090cb341c90bae2a9e5d7fc-1396469693
Conditional redirects found. Visitors from search engines are redirected
to: htxp://gqillqigqilqigqiqlqiigqilqiiiqgg.esmtp.biz/1.php
Redirect to this URL found in 90 sites
See web rep for rediret -> https://www.mywot.com/en/scorecard/gqillqigqilqigqiqlqiigqilqiiiqgg.esmtp.biz?utm_source=addon&utm_content=popup
older exploit: http://malware-traffic-analysis.net/2013/12/27/index.html
Bitdefender TrafficLight blocks redirect. 6 flag: https://www.virustotal.com/nl/url/c02af33d959527e69385136871886bef5812aed9810c9b08976748553a5efbb7/analysis/1396470163/
dynamic dns -> taken down

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!