Author Topic: This site may try to download malicious software notification on taskbar  (Read 1424 times)

0 Members and 1 Guest are viewing this topic.

Offline ygregoriou

  • Newbie
  • *
  • Posts: 12
Hello I was using Facebook and I joined a website that I'm using for years. Basketball.org.cy and for some reason a message in the taskbar came that said this website may try to download malicious software and something was downloading and then it vanished. I've scanned with Avast and Malwarebytes and nothing is found and I don't have anything in recent downloads. Can anyone help me?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: This site may try to download malicious software notification on taskbar
« Reply #1 on: December 12, 2018, 05:36:33 PM »
Hi ygregoriou,

Tracker SSL results:

This website is insecure.
90% of the trackers on this site could be protecting you from NSA snooping. Tell basketball.org.cy to fix it.

Identifiers | All Trackers
 Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.

 -cdnjs.cloudflare.com __cfduid
v1%3a153954085904924275 Twitter guest_id
 basketball.org.cy phpsessid
Legend

 Tracking IDs could be sent safely if this site was secure.

 Tracking IDs do not support secure transmission.

On the IP: https://checkphish.ai/ip/195.14.130.20 & https://cymon.io/195.14.130.180

F-security scan results: https://www.htbridge.com/websec/?id=WMotdVj0
It seems that your system is blocking one of our IPs 192.175.111.228, 192.175.111.229, 64.15.129.102, 64.15.129.106, 70.38.27.248, 72.55.136.156, 72.55.136.199 please whitelist them for successful continuation of the test.

Re: https://toolbar.netcraft.com/site_report?url=http://basketball.org.cy
and  https://www.virustotal.com/#/ip-address/195.14.130.20

Webserver excessive info proliferation detected: Apache/1.3.37 Unix mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.3 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a

754 recommendations for website: https://webhint.io/scanner/fa0d803d-eeb3-4cd1-a111-db4ace6bddd7

Visiting site creates an exclusion in chrome.exe
URLs that redirect found in: -http://basketball.org.cy/el/page/home

1: -http://lightwidget.com/widgets/lightwidget.js -> -https://cdn.lightwidget.com/widgets/lightwidget.js
see: https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=Ynxza3t0YnxsbC5dfWcuXnlge2xgcHxne2BoXW17~enc
Android malware -> https://www.virustotal.com/#/domain/cdn.lightwidget.com

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ygregoriou

  • Newbie
  • *
  • Posts: 12
Re: This site may try to download malicious software notification on taskbar
« Reply #2 on: December 12, 2018, 07:32:44 PM »
That means I have a malware? Because scans found nothing