Author Topic: Index-php malware on website - 5 to flag!  (Read 1007 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33930
  • malware fighter
Index-php malware on website - 5 to flag!
« on: January 28, 2018, 09:36:51 PM »
See: https://www.virustotal.com/#/url/0abb1e9a6abde029bbb688590d51ea77323f790226fe50e7311c31a48176f17f/details
and https://www.virustotal.com/#/domain/saborzuliano.com
See: http://urlquery.net/report/7f3c67c4-2d45-483d-b2e9-46d83c0201b8

DOM-XSS scan results: Results from scanning URL: -http://saborzuliano.com/index.php
Number of sources found: 17
Number of sinks found: 143

Error in script
Quote
-saborzuliano.com/modules/icetabs/assets/15.js benign
     info: [decodingLevel=0] found JavaScript
     error: undefined variable Element
     error: undefined variable Element.Events
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var Element.Events = 1;
          error: line:1: ....^
re
Quote
$$('a.modal-vflow').each(function(el) {
el.addEvent('click', function(e) {
new Event(e).stop();
SqueezeBox.fromElement(el);


Retirable jQuery library: http://retire.insecurity.today/#!/scan/891362f2adb4935efbd671f46486245c3496b1e4014bd3335d3bc519520101a4
error there
Quote
-ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js
     info: [decodingLevel=0] found JavaScript
     error: undefined variable d.style
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var d.style = 1;
          error: line:1: ....^
-> on error near source
Quote
d=s.createElement("div"),f="script"+J();d.style.display="none";d.innerHTML=" <link/><table></table><a href='/a' style='color:red;float:left;opacity:.55;

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: Index-php malware on website - 5 to flag!
« Reply #1 on: January 28, 2018, 09:46:39 PM »
Quote
  Index-php malware on website - 5 to flag!   
7 if you use a fresh scan    ;)


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33930
  • malware fighter
Re: Index-php malware on website - 5 to flag!
« Reply #2 on: January 28, 2018, 11:45:34 PM »
Hi Pondus,

Thanks for the update, it seems they read here  ;D

polonus

P.S. On IP consider also for the particular malware there: https://www.threatcrowd.org/ip.php?ip=184.168.58.1
And nameserver info: https://nameservertool.com/ip/184.168.58.1
« Last Edit: January 28, 2018, 11:53:33 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!