Author Topic: Persistent PHISH - Trust score still 80%?  (Read 921 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34033
  • malware fighter
Persistent PHISH - Trust score still 80%?
« on: October 05, 2017, 03:31:39 PM »
Virus Total suspicious URLs analyser   Failed   Status: dangerous
OpenPhish - phishing site
Kaspersky - phishing site
Malware Domain Blocklist - malicious site
Emsisoft - phishing site
AutoShun - malicious site

Re: https://urlquery.net/report/4fdd9b8c-a91c-41c0-9411-b765253ec7ac
https://threatintelligenceplatform.com/report/bestcareerleap.com/UBQH4CKydm
Query   ?   Found 'src' attribute in `script` tag
Found related JS code  -> http://retire.insecurity.today/#!/scan/18ff2417790039d86daeadf73d5ed614be1a79be53146e6ebe54deddda1b429e


Configuration leak - MySQL (3306)   3306   Port open. Server response: R 5.6.36-cll-lve䌠  K&|_G'+Bÿ÷€K1S05W8Rqd!rmysql_native_password

Sinks and sources: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.bestcareerleap.com

error in:
Quote
wXw.bestcareerleap.com/assets/js/jquery-1.11.3.min.js benign

     info: [decodingLevel=0] found JavaScript
     error: undefined variable n
Something has been added, that is not existing at that very moment kicking up that error (pol),
moreover: Subresource Integrity (SRI) is not implemented, and external scripts are loaded over http

error in bootstrap js -  Bootstrap's JavaScript requires jQuery

F-grade status and recommendations: https://observatory.mozilla.org/analyze.html?host=www.bestcareerleap.com

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!