Author Topic: Redirect to a PHISH or not a PHISH?  (Read 901 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Redirect to a PHISH or not a PHISH?
« on: January 01, 2019, 07:24:12 PM »
See Dr.Web's detecting a redirect: -https://janpreston.us6.list-manage.com/ * redirects to -https://mailchimp.com/about/mcsv-static

Checking: -https://mailchimp.com/about/mcsv-static
Engine version: 7.0.34.11020
Total virus-finding records: 7409140
File size: 635 bytes
File MD5: 4f90b9a1405e494b31d1ea7fb7f5b917

-https://mailchimp.com/about/mcsv-static - Ok
302 moved temp flagged: https://urlquery.net/report/d25380ee-5c3f-426b-9c6d-aa4d284a3de7

IP in Google's PHISHING DB: https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=bXxbbF5oW21wLl5dbWB8Yl11dGBtXnN2LXN0fHRbXg%3D%3D~enc

Not being flagged: https://www.virustotal.com/pl/url/3a6894d8ec059e3e386df2cc1dc5ae75aab1666c990c2f211273763188a2156b/analysis/

* Susceptible to MiM-attacks; X-Powered-By header exposed (more vulnerable to attacks); vulnerable to side-attacks because
HttpOnly cookies not used; e-mails can send fraudulently for SPF is not enabled.

strict-transport-security' header was not specified for -https://mailchimp.com/about/mcsv-static

Not being flagged: https://sitecheck.sucuri.net/results/janpreston.us6.list-manage.com

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!