Author Topic: Hidden malicious iFrames here...  (Read 1878 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Hidden malicious iFrames here...
« on: November 30, 2015, 06:39:54 PM »
Seems that Pernaman already warned against this. Seems that we can confirm his fears.
Here we should also consider that a lot of sub-sites at tumblr dot com are smut sites or sites with explicit content,
and whould therefore be shunned.
See tested: http://test.watchscript.com/ -> Sprawdzany adres www:   -http://losmakemanus.tumblr.com
See: https://www.virustotal.com/nl/domain/losmakemanus.tumblr.com/information/
Various external links could be blocked for ad-tracking: https://urlquery.net/report.php?id=1448904269397
but are not flagged at urlquery...
iFramecheck: Suspicious

-http://assets.tumblr.com/assets/html/like_iframe.html?_v=7e54d4bd89ee867096df32769aefa90c#name=losma'
-http://assets.tumblr.com/assets/html/like_iframe.html?_v=7e54d4bd89ee867096df32769aefa90c#name=losma'
-http://assets.tumblr.com/assets/html/like_iframe.html?_v=7e54d4bd89ee867096df32769aefa90c#name=losma'
'
-https://secure.assets.tumblr.com/assets/html/iframe/o.html?_v=321e518cb9b2cf082d604d6757c75da1#src=h'
-http://assets.tumblr.com/assets/html/iframe/teaser.html?_v=45631c19c03dbcf0e4dc673313d6c70d#src=http'

Google browser difference: Not identical

Google: 60663 bytes       Firefox: 60544 bytes
Diff:         119 bytes

First difference:
tics.html?2c21d514373b9221f5a5041b0dfb079f#" + "-http://losmakemanus.tumblr.com"; function postgamessage() { if (analytics_ifr...

tumblelog.js is not being flagged by VT. -> http://www.domxssscanner.com/scan?url=http%3A%2F%2Fassets.tumblr.com%2Fassets%2Fscripts%2Ftumblelog.js%3F_v%3D454fc1618d865ba96c0749de3c9277c9

See advice: http://stylebot.me/styles/9350  gif not being blocked by ABP!
a try out of it locally
: https://github.com/vikki/fatmanonfilm/blob/master/example_files/iframe.html
and consider: http://codepen.io/mooshlam/pen/jKCxp.html
our pen example -> http://codepen.io/anon/pen/zvgayN

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: November 30, 2015, 06:45:07 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Hidden malicious iFrames here...
« Reply #1 on: December 02, 2015, 10:48:06 PM »
Warning - Do not visit site as it may contain content that could offend some.

Another one of a long list infested with hidden iFrame malcode: http://killmalware.com/not-today-solas.tumblr.com/#
69 sites hosted on IP on that server: not-today-solas.tumblr.com  This is blockable tracking code!
Client peer in New York:
PHP code, consider: http://www.unphp.net/decode/5eafa2507f1932e53d6388bedc286e63/

iFrame check:
Suspicious

-http://not-today-solas.tumblr.com/post/134280496327/photoset_iframe/not-today-solas/tumblr_nyjo90u6n'
-http://not-today-solas.tumblr.com/post/134265452062/photoset_iframe/not-today-solas/tumblr_nxr7osrrx'
-http://not-today-solas.tumblr.com/post/133791674525/photoset_iframe/not-today-solas/tumblr_ngrtyi5br'
-http://not-today-solas.tumblr.com/post/133786576588/photoset_iframe/not-today-solas/tumblr_n9um6ytzh'
-http://not-today-solas.tumblr.com/post/133785820984/photoset_iframe/not-today-solas/tumblr_ngqy5fqem'
'
-https://secure.assets.tumblr.com/assets/html/iframe/o.html?_v=321e518cb9b2cf082d604d6757c75da1#src=h'
-http://assets.tumblr.com/assets/html/iframe/teaser.html?_v=45631c19c03dbcf0e4dc673313d6c70d#src=http'

External links: <-http://33.media.tumblr.com/avatar_3df676d307d0_128.png>; rel=icon
[D] <-http://33.media.tumblr.com/avatar_3df676d307d0_128.png>; rel="shortcut icon"
[D] <-http://not-today-solas.tumblr.com/rss>; rel="alternate"; type="application/rss+xml"
[D] <-http://fonts.googleapis.com/css?family=Libre+Baskerville:400,400italic>; rel="stylesheet"; type="text/css"

Suspicious: -https://px.srvcs.tumblr.com/impixu?T=1449092470&J=eyJ0eXBlIjoidXJsIiwidXJsIjoiaHR0cDpcL1wvbm90LXRvZGF5LXNvbGFzLnR1bWJsci5jb21cLyIsInJlcXR5cGUiOjAsInJvdXRlIjoiXC8ifQ==&U=HPBLLIEEMP&K=5763b6c14d05db8824fa6a6dbb0e1d6d4984061fc04054086ea5cb22e66a0ae3---https://px.srvcs.tumblr.com/impixu?T=1449092470&J=eyJ0eXBlIjoicG9zdCIsInVybCI6Imh0dHA6XC9cL25vdC10b2RheS1zb2xhcy50dW1ibHIuY29tXC8iLCJyZXF0eXBlIjowLCJyb3V0ZSI6IlwvIiwicG9zdHMiOlt7InJvb3RfYmxvZ2lkIjoiMjYzNTQ5NTA2Iiwicm9vdF9wb3N0aWQiOiIxMzQxNDg2

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!