Author Topic: Not only a PHISH, also malicious?  (Read 802 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Not only a PHISH, also malicious?
« on: June 20, 2019, 05:21:38 PM »
Re: https://urlquery.net/report/c8ee1d03-0621-45a9-a26b-9278d520b164
vulnerabilities found and technologies used on IP: https://www.shodan.io/host/111.90.142.67
11 engines to detect: https://www.virustotal.com/gui/url/35ade1947f0967c9b2131e06a1bd0acd610f155a798ded111242a4fc61f87ad2/detection
Malicious activity detected: https://urlscan.io/result/12205f28-f5c9-4cac-9ed3-f9ad6007fdcd
1 vulnerable jQuery library found: https://retire.insecurity.today/#!/scan/5180a6fee603743c16401f95864f34c55d301df5b8f969046ecb77ad28a7798f

The following information contains the analysis of the scan for -http://bethpage.newsecs.com that redirected to
-http://bethpage.newsecs.com/login.php?cmd=login_submit&id=4f4bb69451a1f9eec66e21226664ea144f4bb69451a1f9eec66e21226664ea14&session=4f4bb69451a1f9eec66e21226664ea144f4bb69451a1f9eec66e21226664ea14

Not flagged here: Reputation Check
PASSED
Google Safe Browse: OK
Spamhaus Check: OK
Abuse CC: OK
Dshield Blocklist: OK
Cisco Talos Blacklist: OK
Web Server:
LiteSpeed
X-Powered-By:
PHP/7.0.33
IP Address:
111.90.142.67
Hosting Provider:
Shinjiru Technology Sdn Bhd 
Shared Hosting:
1 sites found on 111.90.142.67

Site is blacklisted, Outdated Software Detected - PHP under 7.3.3

Note! The scan has detected URL(s) from your site and/or IP in Phishing DBs -
This link Flagged URL(s)? will open a utility that will list out any URL(s) from your domain that are listed in Phishing DBs and tell you if Google is currently flagging the URL.
For some tips on clearing a Phishing hack see: Remove a phishing or web forgery warning

If page is loading content, images or scripts, from a site that is currently being flagged as suspicious by Google, it will generate a malware warning -- even if your site is not currently being flagged. About your only option is to remove that content until the site owners can get their site cleaned up and the warning removed.

polonus (volunteer 3rd party cold reconnaissance website security analyst and website error-hunter)

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!