Author Topic: Why only Yandex flags this ads revival site as infested?  (Read 1668 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Why only Yandex flags this ads revival site as infested?
« on: January 17, 2016, 03:00:05 PM »
See: https://yandex.com/infected?l10n=en&url=ads.on-light.de
Sucuri forgets to flag: https://sitecheck.sucuri.net/results/ads.on-light.de
Quttera alerts website as malicious and blacklists right away.
Blacklisted external links:
List of blacklisted external links: 9
-http://ads.on-light.de/www/admin/assets/min.php?g%3Doxp-js&%3Bv%3D3.1.0
-http://ads.on-light.de/www/admin/assets/images/break-el.gif
-http://ads.on-light.de/www/admin/assets/images/login-welcome.gif
-ads.on-light.de/password-recovery.php
-http://ads.on-light.de/www/delivery/fl.js
-http://ads.on-light.de/www/admin/assets/images/favicon.ico
-http://ads.on-light.de/www/admin/index.php
-http://ads.on-light.de/www/admin/assets/images/on-light-logo.png
-http://ads.on-light.de/www/admin/assets/min.php?g%3Doxp-css-ltr&%3Bv%3D3.1.0

Code to be retired: -http://ads.on-light.de
Detected libraries:
jquery - 1.2.6 : -http://ads.on-light.de/www/admin/assets/min.php?g=oxp-js&v=3.1.0
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
1 vulnerable library detected

Re: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fads.on-light.de%2Fwww%2Fadmin%2Findex.php

Tracker tracker report see attached...

This adsite should have been blocked for users with strict adblocking: uBlock₀ has prevented the following page from loading:
hxtp://ads.on-light.de/
Because of the following filter:
-://ads.
Found in: EasyList

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: Why only Yandex flags this ads revival site as infested?
« Reply #1 on: January 17, 2016, 03:11:25 PM »
To check on ck.php we also found this code:
https://searchcode.com/codesearch/view/90954610/
which more than likely also resides here: http://ads.on-light.de/www/delivery/ck.php?ct=

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!