Author Topic: Is this being blocked for us?  (Read 1578 times)

0 Members and 1 Guest are viewing this topic.


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Is this being blocked for us?
« Reply #1 on: April 22, 2020, 04:53:36 PM »
How come I get these "green" results here? -> https://urlscan.io/result/4d94b842-9ab4-4183-9f8b-9019ce03f458
See: https://www.shodan.io/host/23.111.228.4
Website servers dot com is insecure by default
100% of the trackers on this site could be protecting you from NSA snooping.

 All trackers
At least 10 third parties know you are on this webpage.

 -www.servers.com
 -shaaaaaaaaaaaaa.com
 -s3.amazonaws.com
 -proxdevcool.com
 -portal.servers.com
 -Google
 -www.googletagmanager.com
 -static-resource.com
 -cdn-javascript.net
-code.jivosite.com -code.jivosite.com

 Tracker could be tracking safely if this site was secure.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Is this being blocked for us?
« Reply #3 on: April 22, 2020, 05:59:02 PM »
How come I get these "green" results here? -> https://urlscan.io/result/4d94b842-9ab4-4183-9f8b-9019ce03f458
See: https://www.shodan.io/host/23.111.228.4
Website servers dot com is insecure by default
100% of the trackers on this site could be protecting you from NSA snooping.

 All trackers
At least 10 third parties know you are on this webpage.

 -www.servers.com
 -shaaaaaaaaaaaaa.com
 -s3.amazonaws.com
 -proxdevcool.com
 -portal.servers.com
 -Google
 -www.googletagmanager.com
 -static-resource.com
 -cdn-javascript.net
-code.jivosite.com -code.jivosite.com

 Tracker could be tracking safely if this site was secure.

polonus
a check should always start with ... is it up or down   ;)    https://downforeveryoneorjustme.com/proxdevcool.com





« Last Edit: April 22, 2020, 06:06:51 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Is this being blocked for us?
« Reply #4 on: April 22, 2020, 10:10:46 PM »
Hi Pondus,

If that only were that easy.

Main http()s site is down and/or blocked, but occasionally bad malware uri's come from that domain IP.
Malware does not last long as an average, a couple of hours and it may be gone,
persisting malcode is seen seldomly or it might be coming spread by/from a bulletproof hoster.

This one is up now or was some hour ago: https://www.virustotal.com/gui/url/845c7983126bf74ac652b1645dc54801cf528dc1547eb290ab5fdccbf9fa132d/detection

15 engines detect, alas not avast did.

IP kicking up malware, also for mentioned domain:
https://www.virustotal.com/gui/ip-address/88.218.16.218/relations
considering the vulnerabilities at the hoster in Dronten: https://www.shodan.io/host/88.218.16.218
see flaws there and know bootstrap is a can of worms that is exploitable big time

Malware is being taken down as soon as it is being reported and flagged,
does not mean to say that IP is not kicking up new malware like GuLoader and Loki.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!