Author Topic: Genuine fakenews address, infesting android users with AndroidOS/GenBl.3AE5FB  (Read 1106 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Where we found this: httxs://8ch.net/qresearch/res/5262118.html#q5281628
Stems coming from CloudFlare, Google, USA, and info from pure and genuine fake news conspiracy sources.
Quote
Communicating Files
Date scanned
Detections
File type
Name
2019-02-28
1/54
Android
b00e6ffc1806022210e5968a6d1afb5c8b990d205deed31181658cba4408ffc5
Serving up AndroidOS/GenBl.3AE5FB2D!Olympus malcode.

Source also to consider: https://www.shodan.io/host/104.18.105.234

Originates most likely from this campaign source, seen the relation with used zepto technology, with an additional threat record:
https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/
source credits go to #sockpuppet

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Quote
Communicating Files
Date scanned
Detections
File type
Name
2019-02-28
1/54
Android
b00e6ffc1806022210e5968a6d1afb5c8b990d205deed31181658cba4408ffc5
Serving up AndroidOS/GenBl.3AE5FB2D!Olympus malcode.
and a fresh scan say clean   ;)
https://www.virustotal.com/#/file/b00e6ffc1806022210e5968a6d1afb5c8b990d205deed31181658cba4408ffc5/detection




Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Thanks, Pondus, for a second opinion check and final verdict.

Anyways these permissions won't go for me:
Quote
Permissions
android.permission.INTERNET
android.permission.NFC
android.permission.WRITE_EXTERNAL_STORAGE

33 security recommendations for that site: https://webhint.io/scanner/78666eaa-52c3-4b52-a01f-4fe44d3c7a50#Security

polonus
« Last Edit: March 04, 2019, 10:57:40 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!