Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Unknown_html_RFI_shell still on website?
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: Unknown_html_RFI_shell still on website? (Read 898 times)
0 Members and 2 Guests are viewing this topic.
polonus
Avast Überevangelist
Probably Bot
Posts: 34065
malware fighter
Unknown_html_RFI_shell still on website?
«
on:
June 25, 2015, 03:39:49 PM »
See:
https://www.virustotal.com/en-gb/url/211fd45a8d2b456c82652651d1dfb4ad5f3922a932b44b0782f153f34e99f16f/analysis/1435238642/
Nothing detected here:
https://sitecheck.sucuri.net/results/autofrancepoa.blogspot.com.br
IDS alert elsewhere on that IP ->
https://urlquery.net/report.php?id=1435235915620
"ETPRO POLICY telize.com IP lookup". Part of the so-called trojan rules!
Read on background of this malspam:
https://www.metaflows.com/stats/
Consider:
http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fautofrancepoa.blogspot.com.br&useragent=Fetch+useragent&accept_encoding=
For vulnerable code - gapi.iframes:gapi.iframes.style.bubble see what we reported earlier here:
https://forum.avast.com/index.php?topic=167911.0
on navbar-iframe-PHP vulnerability for gapi.iframes:gapi.iframes.style.bubble - so that is three months ago and still abused!
polonus (volunteer website security analyst and website error-hunter)
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Unknown_html_RFI_shell still on website?