Author Topic: XSS attack detected - virus.html.gen03.7 on website detected?  (Read 1121 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
My malware Script Detector v.02b immedeately starts to alert for an XSS atatck on that URL and well on:
-http://rcybc.com/news.asp?bigclass=%C3%83%3F%3F%3F%3F% etc. etc.  is in Dr.Web malicious sites list!
Site potentially harmful -> https://sitecheck.sucuri.net/results/rcybc.com
Norton Safeweb at one time found 22 threats at this website. Not given as safe to visit: https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url=rcybc.com
iFrame included: -http://cache.xixik.com.cn/10/rongcheng/
Quttera detects 28 malicious files: http://quttera.com/detailed_report/rcybc.com
Detected malicious drive-by-download attack
Details:   Malicious obfuscated JavaScript threat 
Code: [Select]
[[DropFileName = "svchost.exe"^^WriteData = ]]malware referer: -http://rcybc.com/rfzn.asp?BigClass=????1u0026SmallClass=...?%C
Cookie: ASPSESSIONIDCAATCCRC=GNDPAFFDKJKOBDIEDGBMCNPD; safedog-flow-item=B1CC6E8369D8737D2CE4921F43E94457 &
Custom errors:Fail and three warnings on: https://asafaweb.com/Scan?Url=rcybc.com
Avast should detect a VBS dropper malware variant here!

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!