Author Topic: Potential suspicious .su domain flagged...  (Read 873 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Potential suspicious .su domain flagged...
« on: January 16, 2018, 11:18:39 PM »
Re: https://urlquery.net/report/a3895517-064d-4d87-aa24-6eeb8e24a6ff
Re: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=eastinvestor.su&ref_sel=GSP2&ua_sel=ff&fs=1

The scan has detected some potential problems in these files. First scroll down through the code listed out after the list of links, this is the code returned by the request for the URL you entered and check for any problems. Next, these link(s) will open the individual URL(s) in this tool, check through the code that is returned, compare the code being returned to a know clean copy, etc.

1 -> /test/fcgi/test.html
2 -> /test/python/test.html
3 -> /test/php/test.html
4 -> /test/perl/test.html
5 -> /test/ssi/test.html
6 -> /index.html

Dom-xss scanner directs to: -htxps://www.banksulutgo.co.id/librari/share/index.php?url=http://goo.gl/KyGqsd/

Abuse from this IP: https://cymon.io/175.103.53.34  like phishing, spam etc. from another domain there.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!