Author Topic: AOS does not flag SE visitors redirects at this website.  (Read 1268 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
AOS does not flag SE visitors redirects at this website.
« on: October 03, 2015, 07:23:19 PM »
See: http://killmalware.com/antropodocus.com/#
See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.antropodocus.com
As expected not flagged here: https://www.virustotal.com/nl/url/e2fcd1b2f1e4bac55ee73b7a6855f30698464e299b5e3524179b6f6427fb8391/analysis/
Sucuri flags:
ISSUE DETECTED   DEFINITION   INFECTED URL
Website Malware   malware-entry-mwhta7?v3   -http://www.antropodocus.com/404testpage4525d2fdc
Website Malware   malware-entry-mwhta7?v3   -http://www.antropodocus.com/404javascript.js
Website Malware   malware-entry-mwhta7?v3   -http://www.antropodocus.com
Website Malware   MW:HTA:7   -http://www.antropodocus.com
Known javascript malware. Details: http://sucuri.net/malware/malware-entry-mwhta7?v3
Location: -http://panamairline.ru/mysave/index.php

Excessive server header info proliferation -> http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Fantropodocus.com%2Finicio.htm
Server redirect to external server: Code: 301,  -http://panamairline.ru/mysave/index.php

See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fantropodocus.com%2Finicio.htm

35 references to blacklisted domain: http://quttera.com/detailed_report/www.antropodocus.com
Detected reference to malicious blacklisted domain -turnitupnow.net **
** bad web rep consider: https://www.mywot.com/en/scorecard/turnitupnow.net?utm_source=addon&utm_content=rw-viewsc
SE redirect is qualified by Quttera as a suspicious file:
index
Severity:   Suspicious
Reason:   Detected suspicious redirection to external web resources at HTTP level. [What's this?]
Details:   Detected HTTP redirection to -http://panamairline.ru/mysave/index.php. *
File size[byte]:   0
File type:   Unknown
Page/File MD5:   00000000000000000000000000000000
Scan duration[sec]:   0.001000

* does not resolve: http://www.ip-adress.com/whois/panamairline.ru
re: http://evuln.com/labs/redirect/panamairline.ru/
Old issues dating back to 2012: http://forum.dobreprogramy.pl/przekierowywanie-wynikow-z-google-na-panamairlineru-i-inne-398689t.html

polonus
« Last Edit: October 03, 2015, 07:25:41 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!