Author Topic: Aurora-infested website..  (Read 1146 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Aurora-infested website..
« on: July 31, 2018, 06:58:43 PM »
See: https://urlquery.net/report/996c4cc0-c1ee-41c3-9f80-4374fd26c4b2
-> https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=spintowin.com-ins.pw&ref_sel=GSP2&ua_sel=ff&fs=1
searching on that IP > https://www.virustotal.com/latest-scan/http://5.8.88.25/login.php (cybercrime tracker net detection).
Alerted: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=5.8.88.25%2Flogin.php&ref_sel=GSP2&ua_sel=ff&fs=1

undefined variable document opened in DOM XSS scan to -http://www.sexcartoon.biz/cgi-bin/atx/out.cgi?id=17&trade=https://www.ps-mojokertoputra.club/berita/author/Poin-Perdana
Number of sources found: 0
Number of sinks found: 11  You are strongly advided by MBAM not to visit this site...

Results from scanning URL: -http://5.8.88.25/lib/bootstrap-3.3.6/js/bootstrap.min.js
Number of sources found: 42
Number of sinks found: 2

Results from scanning URL: -http://5.8.88.25/js/index.js
Number of sources found: 114
Number of sinks found: 99

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!