Author Topic: Is this legit website or probably harmful?  (Read 6169 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Is this legit website or probably harmful?
« on: October 06, 2015, 04:02:56 PM »
Sorry to bother you second day in a row, but I seemed to be sloppy on internet again.  :-[

I was reading siteadvisor.com user reviews on mywot.com and one comment stated that it was "a web fleet management platform by Kentall tech ltd from Cyprus" and had a link to their website kentalltech.com. I got curious and searched little information from Google and visited the said site trough their facebook page: https://www.facebook.com/Kentallhellas. The website itself seemed rather blunt and had some weird "business deal" banners, which showed even with Adblock on. Sucuri shows site to be clean, though it also shows content error. Quterra shows clean too. Sites like Norton, Google Safe Browsing, or Siteadvisor seem to have no reports on the said website.

https://sitecheck.sucuri.net/results/www.kentalltech.com

http://quttera.com/detailed_report/www.kentalltech.com

After some more Googling I found that Google autocorrected the name into "Kendall tech", which seemed to be online IT service website, and then I started to think if "Kentalltech.com" I visited was some kind of fake trash/spam site...

Any help would be very appreciated.
« Last Edit: October 06, 2015, 05:16:07 PM by Pernaman »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Is this legit website or probably harmful?
« Reply #1 on: October 06, 2015, 05:27:45 PM »
« Last Edit: October 06, 2015, 05:54:59 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Is this legit website or probably harmful?
« Reply #2 on: October 06, 2015, 05:57:54 PM »
An interesting posting again, Pernaman.
Lets analyse this link by link. First we see some bad SEO web rep here: https://www.mywot.com/en/scorecard/frog.wix.com?utm_source=addon&utm_content=popup-rate#rate
Here I do not see much alerted: https://urlquery.net/report.php?id=1444142108382
We see a redirect to: -static.parastorage.com  and there is GoDaddy abuse goin'on:
https://www.virustotal.com/nl/domain/static.parastorage.com/information/
with Avast detecting VBS:Dropper-DF [Trj] & a detection Avast does not have (yet): https://www.virustotal.com/nl/file/04fa44c30654de8c68df61fca5969f0e9757618e63854e65a34ca59b1be10ad2/analysis/
Then there is a link to -static.wixstatic.com, see: https://www.virustotal.com/nl/domain/static.wixstatic.com/information/
Re: https://www.virustotal.com/nl/domain/static.wixstatic.com/information/
See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.kentalltech.com
Google Browser difference:
Not identical

Google: 53738 bytes       Firefox: 48696 bytes
Diff:         5042 bytes

First difference:
ent="app200.vac.aws"/> <meta http-equiv="x-wix-meta-site-id" content="12c9076d-6238-eeb1-f6b1-030155e76d98"/> <meta http-equiv="x-wix-application-instance-id" content="98390f1...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Is this legit website or probably harmful?
« Reply #3 on: October 06, 2015, 06:04:11 PM »
Yikes... Could this mean I maganed to get something malicious into my machine then?  :o

REDACTED

  • Guest
Re: Is this legit website or probably harmful?
« Reply #4 on: October 07, 2015, 02:38:47 PM »
I haven't noticed anything unusual in my computer, but I decided to try do some logs just in case...

I hope someone would have time to look these up  :)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Is this legit website or probably harmful?
« Reply #5 on: October 07, 2015, 05:00:18 PM »
I asked for a qualified malware remover here to go over the logs.
Please wait patiently for him to show up and follow his instructions to the dot.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this legit website or probably harmful?
« Reply #6 on: October 07, 2015, 05:12:35 PM »
Looks clean to me :)

REDACTED

  • Guest
Re: Is this legit website or probably harmful?
« Reply #7 on: October 07, 2015, 10:53:33 PM »
Thank you for your time  ;D Now could you provide me link into the program that's used to remove Farbar and aswMBR (I cannot remember it's name...) or can I just remove them manually?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Is this legit website or probably harmful?
« Reply #8 on: October 07, 2015, 11:04:11 PM »
As they are not installed you can just right click and delete


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this legit website or probably harmful?
« Reply #9 on: October 07, 2015, 11:19:12 PM »

Remove tools

Download and run Delfix
Select the options as shown