Author Topic: 4 engines detect this website laden with malware Heodo  (Read 1179 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
4 engines detect this website laden with malware Heodo
« on: October 03, 2019, 11:10:06 PM »
Re: https://urlhaus.abuse.ch/url/237295/
Blacklisted (3): https://sitecheck.sucuri.net/results/pl.thevoucherstop.com/wp-admin/xdx66dy1/
Various instances give the site as clean, Google Safe Browse: OK ; Spamhaus Check: OK ;
Abuse CC: OK ; Dshield Blocklist: OK ; Cisco Talos Blacklist
4 engines will detect this URL: https://www.virustotal.com/gui/url/89400101bae600c6cb244737b68d01c938d51fc150793022c2339f994d3e56b3/detection
On IP see: https://www.shodan.io/host/173.198.199.5

Infesting with -/////MZ@   !L!This program cannot be run in DOS mode. etc//////

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: 4 engines detect this website laden with malware Heodo
« Reply #1 on: October 03, 2019, 11:22:24 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: 4 engines detect this website laden with malware Heodo
« Reply #2 on: October 03, 2019, 11:37:00 PM »
Thanks Pondus, the more the better  :D (well actually 8 now as you count the engine, flagging it as suspicious);
the 4 that flagged it initially was at the time URLHaus member reported, then another three jumped the detection wagon.

Other domains on that IP:
-au.thevoucherstop.com
-be.thevoucherstop.com
-de.thevoucherstop.com
-es.thevoucherstop.com
-fr.thevoucherstop.com
-in.thevoucherstop.com
-it.thevoucherstop.com
-nl.thevoucherstop.com
-pl.thevoucherstop.com
-pt.thevoucherstop.com
-ro.thevoucherstop.com
-test.thevoucherstop.com
-thevoucherstop.com
-tr.thevoucherstop.com
-uk.thevoucherstop.com
-www.thevoucherstop.com

pol

« Last Edit: October 03, 2019, 11:39:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!