Author Topic: Trojan Embedded in Disqus?  (Read 2888 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Trojan Embedded in Disqus?
« on: July 26, 2016, 07:34:09 PM »
Hello All,

User of the animehaven site animehaven.to
Recently site got added to blacklist, which struck me as odd since I enjoyed weeks of problem and intrusion free browsing.

After adding the website to exclusions to get past the URL:Mal filter, I get another infection warning in regards to:
Object: http://disqus.com/embed/comments/?base=default
Infection: JS:ScriptPE-inf[Trj]


This only pops on pages with individual anime episodes, not the main page, or show listings. Only on pages with Disqus enabled.
My question is: is this valid or not? I suppose there is a possibility of a tool like Disqus becoming compromised. And I've seen it one other time here: https://disqus.com/home/channel/discussdisqus/discussion/channel-discussdisqus/trojan_virus_notifications/ But I'm curious as to if this is actually possible.
Or is this all some silly FP?




Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: Trojan Embedded in Disqus?
« Reply #1 on: July 27, 2016, 01:06:46 AM »
Hello.

I do not see any alert  on here.Site animehaven.to not is blocked

hxxp://disqus.com/embed/comments/?base=default

at least at no time was notification the avast,seems already to have been fixed.


Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Trojan Embedded in Disqus?
« Reply #2 on: July 27, 2016, 09:14:34 AM »
I can see many hits with disqus[.]com domain and JS:ScriptPE-inf detection in our statistics. Many were caused by us blocking animehaven[.]to, which we have unblocked around 6 hours ago, but many are caused by loading resources from apparently malicious sites (for example gmil[.]com). I cannot say which cause your case was (without inquiring additional details), but you should soon find out - if it was caused by animehaven, you shouldn't be getting any more alerts.