Author Topic: Dangerous websites to block  (Read 8295 times)

0 Members and 1 Guest are viewing this topic.

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Dangerous websites to block
« on: March 17, 2018, 08:10:16 PM »

hackingloops*com
wifipasser*com

These urls are all scam and dangerous, some are redirecting to offers with porn games!

Please update your database urgently!

Thanks

Chris
« Last Edit: March 29, 2018, 10:33:10 PM by Christophe2 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Dangerous websites to block
« Reply #1 on: March 17, 2018, 08:47:33 PM »
-> https://support.avast.com/article/258/ (Reporting Malware Samples)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #2 on: March 17, 2018, 08:50:41 PM »
Hi,

I did but not answer and the websites are still not blocked!

It's urgent!

Thanks

Chris

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Dangerous websites to block
« Reply #3 on: March 17, 2018, 09:45:55 PM »
I have blocked most of the URLs now.
Just to point a couple of things out:
- we do not normally reply to malware submissions, so the "no answer" status is perfectly normal;
- some of the URLs are not scammy in any way and therefore there is no reason for them to be blocked;
- some of the URLs are at least 2 years old (so there is little urgency);
- some of the URLs have been blocked for a couple of years already.
H.

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #4 on: March 18, 2018, 09:30:28 AM »
Hi,


Thanks

Chris
« Last Edit: March 29, 2018, 10:33:59 PM by Christophe2 »

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: Dangerous websites to block
« Reply #5 on: March 18, 2018, 02:34:28 PM »
Hi Christophe2,

When we look for instance at facepirater*com, we see that the origin of the website has been hidden through PrivacyGuardian dot org.
Re: https://www.scamadviser.com/check-website/facepirater.com

Moreover full of errors and alerts here: https://privacyscore.org/site/94025/

Cloudflare abuse and considerable risk here: https://toolbar.netcraft.com/site_report?url=dc-ec1241b79c0a.facepirater.com
Hosted from Bulgaria through -blue.warez-host.com  with ethical problems for warez and phishing involved: https://community.homeaway.com/thread/6557

Also consider: https://urlscan.io/domain/facepirater.com  Nothing hosted on and nothing talking to this domain.
151 PHISHING alerts for IP: https://checkphish.ai/ip/104.24.120.59  (plain request cloudflare-nginx abuse).

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #6 on: March 18, 2018, 05:26:51 PM »
Hi,

Thanks for your reply.

This website phish credit card information with a fake credit card form.

It should be blocked urgently!

Thanks

Best Regards

Chris

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: Dangerous websites to block
« Reply #7 on: March 18, 2018, 07:00:38 PM »
Thank you for the heads-up on these "hidden location" domains, Christophe2,
because that "" is the common denominator here,
and domains that have something to hide are suspicious by our standards,
and also cannot be trusted as a rule of thumb.

For just another website (from the country where I reside in, from Roosendaal in the Netherlands),
one domain which you provided for us to look into:
https://www.scamadviser.com/check-website/wifipasser.com

The website location is being hidden by Panamanian Whois Guard Protected Ltd.
Deemed to be popular but with a very low trust rating ('naturellement revenant'  :o )

CMS issues and misconfiguration:
Quote
Warning  Directory Indexing Enabled

In the test we attempted to list the directory contents of the uploads
and plugins folders to determine if Directory Indexing is enabled.

This is an information leakage vulnerability that can reveal sensitive information
regarding your site configuration or content.

/wp-content/uploads/ enabled
/wp-content/plugins/ disabled
Directory indexing was tested on the /wp-content/uploads/ and /wp-content/plugins/ directores. Note that other directories may have this web server feature enabled, so ensure you check other folders in your installation. It is good practice to ensure directory indexing is disabled for your full WordPress installation either through the web server configuration or .htaccess.

Various issues: https://privacyscore.org/site/94080/

Several jQuery libraries to be retired: https://privacyscore.org/site/94080/

Also consider: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=wifipasser.com&ref_sel=GSP2&ua_sel=ff&fs=1

7 to flag here: https://www.virustotal.com/#/url/d5585ea54c471ad8271301d960dc2727dfdd1a2e7942a532a9ebce5e1f426699/detection

Quite some PHISHING going on on IP: https://checkphish.ai/ip/185.66.141.146   -> http://whois.domaintools.com/185.66.141.146

PHISHING confirmed here: https://urlquery.net/report/24905d3e-5882-4948-a1b1-0059ae947425

Bien à vous,

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: March 18, 2018, 07:07:58 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #8 on: March 18, 2018, 08:10:28 PM »
Hi,

Thanks for your reply.

Did you blocked all the websites url I mentionned before?

Thanks

Best Regards

Chris

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Dangerous websites to block
« Reply #9 on: March 18, 2018, 09:24:17 PM »
I have blocked most of the URLs now.

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #10 on: March 18, 2018, 10:43:26 PM »


it is a phishing website that ask credit card information with a fake paymenr form!!!
« Last Edit: March 29, 2018, 10:34:26 PM by Christophe2 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Dangerous websites to block
« Reply #11 on: March 19, 2018, 12:50:04 AM »
Hi Chris,

I've viewed the website facepirater*com. They're not asking for payment anywhere that I've seen.

The most questionable thing I've seen is of course it's a hacking website for FB. It won't actually hack anything. They're asking you to call a phone number, which won't do anything. (Except maybe charge you high fees? *Don't call the phone number)

I don't know if you've actually called this number and found out what they want - but it's sufficed to say that people looking to "hack" a Facebook account are probably looking for a one-step click fix. Not a multi-step hack that involves calling people.

I can think of far easier ways to gain someones credentials. (Programs exist to do this. Chrome has historically saved "auto-fill" passwords in plain text. I'm not sure they still do, but I wouldn't be surprised.)

So, it's not a phishing website, but it's not something that Avast! should be allowing either. (Given it's questionable nature)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Dangerous websites to block
« Reply #12 on: March 19, 2018, 06:32:25 AM »
The detection for facepirater is live since 23.09. 2017, 17:19 CET, here is what happens when I try to open it on my computer:



(Please note that "Phishing" doesn't mean that it steals your credit card info, but we only have two "visible/outside" types - URL:Mal (malicious) and URL:Phishing (phishing) - and this one tends to be more of the second type.)

Where do you see it as clean?
« Last Edit: March 19, 2018, 06:34:54 AM by HonzaZ »

Offline Christophe2

  • Jr. Member
  • **
  • Posts: 44
Re: Dangerous websites to block
« Reply #13 on: March 19, 2018, 08:48:30 AM »


Thanks

Chris
« Last Edit: March 29, 2018, 10:34:45 PM by Christophe2 »

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Dangerous websites to block
« Reply #14 on: March 19, 2018, 09:05:25 AM »
I see. So the AOS (Avast Online Security, the browser plugin) doesn't recognize URLs marked as URL:Phishing. This is certainly a bug, and I think I know how to fix it. I even have two solutions, one is fast and one is good (as it always happens to be). I will let you guys know when I decide which solution to implement and what the ETA is.
Thanks for reporting the bug!