Author Topic: Is this malware being detected?  (Read 770 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Is this malware being detected?
« on: May 23, 2019, 07:45:59 PM »
Re: https://www.virustotal.com/#/url/5b616d5bba5c7cac6c7e0a36da6da6e80b53511b55e15d8cc46e27ded71816f9/detection
See: https://urlquery.net/report/1709d8dd-7ec7-44a0-980c-2af64da01949
malware: https://zulu.zscaler.com/submission/f73361da-7b03-4345-89a3-9cd42b3e9e6c

Retire.js
bootstrap   3.2.0   Found in -http://softfreeway.com/Stark/thevic/js/bootstrap.min.js
Vulnerability info:
High   28236 XSS in data-template, data-content and data-title properties of tooltip/popover CVE-2019-8331   
Medium   20184 XSS in data-target property of scrollspy CVE-2018-14041   
Medium   20184 XSS in collapse data-parent attribute CVE-2018-14040   
Medium   20184 XSS in data-container property of tooltip CVE-2018-14042   
jquery   1.11.1   Found in -https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js
Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   1234
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   123
Medium   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution   123
dont check   www   Found in https://www.google-analytics.com/ga.js

* checked Retire.js
Retire.js
angularjs   1.6.6   Found in -https://ajax.googleapis.com/ajax/libs/angularjs/1.6.6/angular.min.js
Vulnerability info:
Low   XSS through SVG if enableSvg is set   12
angularjs   1.6.6   Found in -https://ajax.googleapis.com/ajax/libs/angularjs/1.6.6/angular-animate.min.js
Vulnerability info:
Low   XSS through SVG if enableSvg is set   12
angularjs   1.6.6   Found in -https://ajax.googleapis.com/ajax/libs/angularjs/1.6.6/angular-touch.min.js
Vulnerability info:
Low   XSS through SVG if enableSvg is set

Detection on IP: https://www.virustotal.com/de/ip-address/195.211.101.87/information/

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!