Author Topic: JS.Agent-156 on website detected?  (Read 993 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
JS.Agent-156 on website detected?
« on: August 03, 2015, 01:47:28 PM »
See: https://www.virustotal.com/nl/url/1a7d0959a2d9a8ba5cf9b5c7d2c21e7cc0fbc4ac5c3d8d897670f35bd1b65563/analysis/1438600128/
See: http://quttera.com/detailed_report/zzxfyy8.com  46 malicious files detected.
Severity:   Malicious
Reason:   Detected reference to blacklisted domain
Details:   Detected reference to malicious blacklisted domain web.nba1001.net *
List of referenced blacklisted domains/hosts: 2
-web.nba1001.net
-zzxfyy8.com

Blacklisted website and
ISSUE DETECTED   DEFINITION   INFECTED URL
Website Malware   malware-entry-mwanomalysp8   htxp://zzxfyy8.com/news_cy.asp?articleid=1215
Website Malware   MW:BLK:2   htxp://zzxfyy8.com
Anomaly behavior detected (possible malware). Details: http://sucuri.net/malware/malware-entry-mwanomalysp8
<script type="text/javascript" src="htxp://web.nba1001.net:8888/tj/tongji.js"></script>

Three warnings on scan: -https://asafaweb.com/Scan?Url=zzxfyy8.com%2Fcpzs1.asp%3Fpage_no%3D14

I get a 500 Internal Server Error site susceptible to Close QQ backdoor? -> http://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/worm_qqpass.bfn  Avast could detect malware as HTML:Includer-AG [Trj]

See tracker tracker report attached, mainly Baidu ads tracking.

* Re: https://www.virustotal.com/nl/url/802c247f8749f6a208f1a247dcb9ca3b28f8dfec881fb91e49a1f5e8645f7aa6/analysis/
and historically: http://www.strazzere.com/blog/2013/02/javascript-malware-cross-contamination-in-android-apks/
Cannot be fetched!

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!