Author Topic: Malware site - what resides here?  (Read 1078 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Malware site - what resides here?
« on: September 04, 2015, 01:05:12 PM »
See website risk status 7 red out of 10: http://toolbar.netcraft.com/site_report?url=http://hgf43.bigalbailbond.com
-flagged by Google safebrowsing as malicious: -http://hgf43.bigalbailbond.com/
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=hgf43.bigalbailbond.com
2 warnings: https://asafaweb.com/Scan?Url=hgf43.bigalbailbond.com
received data:
Quote
1. HTTP/1.1 200 OK\r\n
Server: nginx/1.2.1\r\n
Date: Fri, 04 Sep 2015 10:45:38 GMT\r\n
Content-Type: text/html\r\n
Content-Length: 38\r\n
Connection: keep-alive\r\n
X-Powered-By: PHP/5.4.36-0 deb7u3\r\n
Vary: Accept-Encoding\r\n
Content-Encoding: gzip\r\n
\r\n
my·one·more·chance
System Details:
Running on: nginx/1.2.1
Powered by: PHP/5.4.36-0+deb7u3
Outdated Web Server Nginx Found: nginx/1.2.1

Blacklisted by Quttera labs. Re: https://www.virustotal.com/nl/url/2617b1472c4058b7f491b89d5fc90813669decb35c27871602428ddddf0c8638/analysis/1441363434/
sub domain on bad zone: http://www.dnsinspect.com/bigalbailbond.com/1441364258

Another GoDaddy.com abuse case: GD-DOMAINS.COM
22569 Domains Registered On 06/13/2015

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!