Author Topic: IDs alerts on website denoting a problem?  (Read 900 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
IDs alerts on website denoting a problem?
« on: October 24, 2017, 03:41:17 PM »
Nothing found here: https://www.virustotal.com/#/url/46512e7dbde93dffe4306b715ad187c052bf5ddf6ee13c43144ce05af63f60d5/detection
neither here: http://isithacked.com/check/postelgroup.com
nor here: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=postelgroup.com%2Findex.php%2Fen%2F&ref_sel=GSP2&ua_sel=ff&fs=1

But not given the all green here: http://urlquery.net/report/75239ea3-25f0-4f44-94d4-a38b5eead635
e.g.
Quote
Suricata /w Emerging Threats Pro   
Timestamp   Severity   Source IP   Destination IP   Alert
2017-10-24 15:09:11 CEST   2   AS32475 SingleHop 173.236.66.190   Client IP   ET WEB_CLIENT Hex Obfuscation of document.write % Encoding
2017-10-24 15:09:11 CEST   2   AS32475 SingleHop 173.236.66.190   Client IP   ET WEB_CLIENT Hex Obfuscation of String.fromCharCode % Encoding
2017-10-24 15:09:11 CEST   2   AS32475 SingleHop 173.236.66.190   Client IP   ET WEB_CLIENT Hex Obfuscation of charCodeAt % Encoding

Retirable jQuery library code: http://retire.insecurity.today/#!/scan/27d3bbe6ca131a106f647afbebb2dd59067f01b6ae94a4e8c452292599546775

error in code here:
Quote
(script) postelgroup.com/media/jui/js/jquery.min.js
     status: (referer=postelgroup.com/)
   
     info: [decodingLevel=0] found JavaScript
     error: undefined variable n
     suspicious: maxruntime exceeded 10 seconds     
Quote
postelgroup.com/modules/11/tmpl/sliderengine/amazingslider.js  found JavaScript
     error: undefined variable jQuery
     error: undefined variable $.fn
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var $.fn = 1;
          error: line:1: ....^
script.js error
Quote
  found JavaScript
     error: undefined variable jQuery
     error: undefined variable $.fn
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var $.fn = 1;
          error: line:1: ....^

Consider: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fpostelgroup.com%2Findex.php%2Fen%2F
and F-grade status and recommendations: https://observatory.mozilla.org/analyze.html?host=postelgroup.com

Also 19 issues detected here: https://privacyscore.org/site/33728/

Phishing attack detected: Location: -https://postelgroup.com/bin/0wa1

Outdated Joomla version - Google safe browse check
WARNING
Google finds the site to be potentially dangerous.

polonus (volunteer website security analyst and webmail error hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!