Author Topic: constantly message of connection aborted ... 21656496f07761af42.js  (Read 2704 times)

0 Members and 1 Guest are viewing this topic.

Offline Daniel F.

  • Newbie
  • *
  • Posts: 4
Hi,
Using Chome, I found that every page I load, this file is trying to be loaded:

s3.amazonaws.com/jsfile/21656496f07761af42.js

even an empty html page, from my loaclhost.

It happen on both machines i have, with Chrome and the same user account, so all the extensions are loaded in both.

Is it loaded from an extension... ?
or something native from Chrome...?

is it a real virus...?

Thanks in advance.
Daniel.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #1 on: January 08, 2020, 03:06:09 PM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Daniel F.

  • Newbie
  • *
  • Posts: 4
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #2 on: January 09, 2020, 04:10:28 AM »
...the logs...

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #3 on: January 09, 2020, 04:22:29 AM »
Can you find and attach Addition.txt please? (Should be located in this folder: C:\Users\lenovo\Downloads)

Are you a developer by chance? I'm seeing a lot of webpage application software (Github, MySQL, HeidiSQL, HTTPD, etc).

Also, in an elevated command prompt (Right click -> "Run as Admin"), type the following command? netstat -a -n -b > output.txt

The file will be located in C:\Windows\System32\output.txt. Please attach that file as well.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Daniel F.

  • Newbie
  • *
  • Posts: 4
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #4 on: January 09, 2020, 01:04:00 PM »
Yes, I'm a developer.

Attached are the required files.

Thanks.


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #5 on: January 09, 2020, 02:49:20 PM »
Yes, I'm a developer.

Attached are the required files.

Thanks.

Sass Drake will be around likely before the end of the day.

I had a look at the JS code sitting on the AWS server. It's appeared heavily obfuscated.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
« Last Edit: January 09, 2020, 04:29:59 PM by Pondus »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #7 on: January 09, 2020, 05:08:45 PM »
Looks clean to me. Can you try to disable  Chrome extensions one by one until Avast detections stops?

Offline Daniel F.

  • Newbie
  • *
  • Posts: 4
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #8 on: January 09, 2020, 06:54:49 PM »
Well @Sass...
It looks like it is the extension "Best Draw.io Diagram Tool"
(https://chrome.google.com/webstore/detail/best-drawio-diagram-tool/cchkdgeljiellkglonkiciahfdhnpcen)

I'm thinking it's a wrapper (and fake) for draw.io...

Extension Details:

Description
draw.io is free online software for creating flowcharts and various diagrams.
Version
3.3
Size
< 1 MB
ID
cchkdgeljiellkglonkiciahfdhnpcen
Inspect views
No active views
Permissions
Read your browsing history
Site access
Allow this extension to read and change all your data on websites you visit:
On click
On specific sites
On all sites  << It is ON

Allow in incognito  [Off]
Warning: Google Chrome cannot prevent extensions from recording your browsing history. To disable this extension in incognito mode, unselect this option.
Allow access to file URLs  [Off]
Collect errors  [Off]

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: constantly message of connection aborted ... 21656496f07761af42.js
« Reply #9 on: January 09, 2020, 10:34:14 PM »
Please report status when that extension is disabled.