Author Topic: Is this PHISHING being detected?  (Read 4991 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Is this PHISHING being detected?
« on: February 06, 2018, 11:14:58 PM »
Example
Quote
Location: htxp://passiveprofitstream.com/wp-content/themes/optimizePressTheme/lib/assets/images/bullet_block/32x32/jiSLjcf5JLoTBSf8eMcIFcMN55ZpyIPocEyM0dVh66dkdNQuwSvSambfnsVTJj6vlTw2vZdAbyiWPggDJg7wAslKmHrAtdjcm3BnXPPztK81prCUhxwIxhfMikLTiOgh/home
See other instances: https://urlquery.net/report/a10ce4c8-8aed-4cf6-a839-047e8bb4dd3d
Detected and given as  compromised site: https://sitecheck.sucuri.net/results/passiveprofitstream.com#sitecheck-details

Quote
  Loaded Resources

Compromised sites will often be linked to malicious javascript or iframes in an attempt to attack users of your WordPress installation. Look over the listed resources, you should be familiar with all scripts and investigate ones you are not sure. In addition removal of unneeded javascript will speed up your website.

-http://passiveprofitstream.com/
GoogleSafe:
OK   Load:
2066ms   Server: -67.225.162.192
Apache   ASN: 32244 United-States
Liquid Web, L.L.C   Reverse DNS:
-host.nateleung.com
-https://js.center.io/center.js
GoogleSafe:
OK   Load:
94ms   Server: -172.217.7.147
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f147.1e100.net
-https://my.leadpages.net/static/lp1510058504/public/css/leadpage.css
GoogleSafe:
OK   Load:
99ms   Server: -72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://my.leadpages.net/static/lp1510058504/public/js/leadpage.js
GoogleSafe:
OK   Load:
118ms   Server: -72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://static.lpages.co/YzgRUBBKJXZTeY2bTDRt3F/css/style.css
GoogleSafe:
OK   Load:
326ms   Server: -130.211.9.117
UploadServer   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-117.9.211.130.bc.googleusercontent.com
-https://static.lpages.co/YzgRUBBKJXZTeY2bTDRt3F/js/html5shiv.js
GoogleSafe:
OK   Load:
350ms   Server: -130.211.9.117
UploadServer   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-117.9.211.130.bc.googleusercontent.com
-https://static.lpages.co/YzgRUBBKJXZTeY2bTDRt3F/js/jquery.js
GoogleSafe:
OK   Load:
338ms   Server: 130.211.9.117
UploadServer   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-117.9.211.130.bc.googleusercontent.com
-https://static.lpages.co/YzgRUBBKJXZTeY2bTDRt3F/js/jquery-migrate.js
GoogleSafe:
OK   Load:
329ms   Server: -130.211.9.117
UploadServer   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-117.9.211.130.bc.googleusercontent.com
-https://static.lpages.co/YzgRUBBKJXZTeY2bTDRt3F/js/functions.js
GoogleSafe:
OK   Load:
329ms   Server: -130.211.9.117
UploadServer   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-117.9.211.130.bc.googleusercontent.com
-http://my.leadpages.net/static/lp1510058504/min/tracking.js
GoogleSafe:
OK   Load:
72ms   Server: -72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://js.center.io/identify.html
GoogleSafe:
OK   Load:
14ms   Server: -172.217.7.147
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f147.1e100.net
-https://api.leadpages.io/analytics/v1/events/capture?k=view&a=leadpage&l=5765606242516992&v=&e=&pid=Cqodq4xTaAuxDVrKGr4Tbb&uid=VJJj2Zz47nmaVYH72hrRid&sid=V2VbLbhyv228M4vzU3gg74&cid=lp-5765606242516992&uri=-http%3A%2F%2Fpassiveprofitstream.com%2F&rf=&rx=400&ry=300&tz=%2B00%3A00
GoogleSafe:
OK   Load:
137ms   Server: -130.211.20.100
Stargate   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-100.20.211.130.bc.googleusercontent.com
-http://device.lpusercontent.com/leadbox/147bc2c73f72a2:165aa6703346dc/5699257587728384/?lp-in-iframe=1&__fromjs=1
GoogleSafe:
OK   Load:
330ms   Server: -35.202.21.90
Leadpages   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-90.21.202.35.bc.googleusercontent.com
-http://ajax.googleapis.com/ajax/libs/webfont/1/webfont.js?_=1517937806500
GoogleSafe:
OK   Load:
24ms   Server: -172.217.7.234
sffe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad23s58-in-f10.1e100.net
-https://connect.facebook.net/en_US/all.js#xfbml=1
GoogleSafe:
OK   Load:
32ms   Server: -31.13.69.203
ASN: 32934 United-States
Facebook, Inc.   Reverse DNS:
-xx-fbcdn-shv-01-iad3.fbcdn.net
-https://platform.twitter.com/widgets.js
GoogleSafe:
OK   Load:
215ms   Server: -192.229.163.25
ECS (dca/2490)   ASN: 15133 United-States
MCI Communications Services, Inc. d/b/a Verizon Business   Reverse DNS:
-https://apis.google.com/js/plusone.js?onload=onPlusOneLoadCallback
GoogleSafe:
OK   Load:
107ms   Server: -172.217.7.142
ESF   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f142.1e100.net
-http://fonts.googleapis.com/css?family=Open+Sans
GoogleSafe:
OK   Load:
42ms   Server: -172.217.7.138
ESF   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f138.1e100.net
-http://staticxx.facebook.com/connect/xd_arbiter/r/lY4eZXm_YWu.js?version=42#channel=f3e906450c&origin=http%3A%2F%2Fpassiveprofitstream.com
GoogleSafe:
OK   Load:
25ms   Server: -31.13.69.203
ASN: 32934 United-States
Facebook, Inc.   Reverse DNS:
-xx-fbcdn-shv-01-iad3.fbcdn.net
-https://staticxx.facebook.com/connect/xd_arbiter/r/lY4eZXm_YWu.js?version=42#channel=f3e906450c&origin=http%3A%2F%2Fpassiveprofitstream.com
GoogleSafe:
OK   Load:
51ms   Server: -31.13.69.203
ASN: 32934 United-States
Facebook, Inc.   Reverse DNS:
-xx-fbcdn-shv-01-iad3.fbcdn.net
-http://fonts.gstatic.com/s/opensans/v15/cJZKeOuBrn4kERxqtaUH3T8E0i7KZn-EPnyo3HZu7kw.woff
GoogleSafe:
OK   Load:
43ms   Server: 1-72.217.7.131
sffe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f3.1e100.net
-https://apis.google.com/_/scs/apps-static/_/js/k=oz.gapi.en_US.7s-fzj_vtzE.O/m=plusone/rt=j/sv=1/d=1/ed=1/am=AQE/rs=AGLTcCPE0tI5pp5weCjmJoGcBGjk07QMMQ/cb=gapi.loaded_0
GoogleSafe:
OK   Load:
15ms   Server: -172.217.7.142
sffe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
-iad30s08-in-f142.1e100.net
-https://platform.twitter.com/widgets/widget_iframe.02a1dca8703a0f5962a962619634825b.html?origin=http%3A%2F%2Fpassiveprofitstream.com
GoogleSafe:
OK   Load:
17ms   Server: -192.229.163.25
ECS (dca/2469)   ASN: 15133 United-States
MCI Communications Services, Inc. d/b/a Verizon Business   Reverse DNS: 

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Is this PHISHING being detected?
« Reply #1 on: February 08, 2018, 02:15:26 PM »
Well, that is, what this extension is for:

https://toolbar.netcraft.com/install