Author Topic: Low Security risk site infested with Generic Find or FP?  (Read 937 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
See: https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=d3d3Lndbc2hiWy5eXW1g~enc
Consider collapse.js -> -https://www.wishbi.com/wp-content/themes/ipinpro/js/collapse.js
Bootstrap: collapse.js v3.3.6
* -http://getbootstrap.com/javascript/#collapse

Re: https://sitecheck.sucuri.net/results/www.whisbi.com
Consider: https://maltiverse.com/hostname/static.whisbi.com

Given as clean here: https://online.drweb.com/result/?lng=en&chromeplugin=1&url=http%3A%2F%2Fwww.whisbi.com
No detection: https://www.virustotal.com/gui/url/b2ce36b632e0620d89b0da281ada790fb661095de1d788e701c33380e659cb96/detection

TLS Recommendations
Password input field detected on an unencrypted HTTP page. Please use HTTPS protocol to protect login forms:
-http://static.wishbi.com/.git/HEAD
-http://static.wishbi.com/404javascript.js
-http://static.wishbi.com/404testpage4525d2fdc

HTTPS mixed content found. Your HTTPS website is referring to an HTTP resource:
-http://html5shim.googlecode.com/svn/trunk/html5.js on -https://www.wishbi.com/
-http://html5shim.googlecode.com/svn/trunk/html5.js on -https://www.wishbi.com/login/
-http://html5shim.googlecode.com/svn/trunk/html5.js on -https://www.wishbi.com/login/?redirect_to=/
-http://html5shim.googlecode.com/svn/trunk/html5.js on -https://www.wishbi.com/signup/

See: https://sitecheck.sucuri.net/results/static.wishbi.com

Generic Malware Google abuse or an FP?

polonus (volunteer 3rd part cold recon website security analyst and website error-hunter)
« Last Edit: May 25, 2020, 04:48:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
Re: Low Security risk site infested with Generic Find or FP?
« Reply #1 on: May 25, 2020, 04:56:45 PM »
Consider Results from scanning URL: -http://www.whisby.com/wp-admin/admin-ajax.php
Quote
<!doctype html><html lang="en"><head><meta http-equiv="content-type" content="text/html;charset=utf-8"><meta name="viewport" content="width=device-width,initial-scale=1"><link rel="shortcut icon" href="data:image/x-icon;," type="image/x-icon"><title></title><script src="htxps://www.google.com/adsense/domains/caf.js" type="text/javascript"></script><noscript><style>#content-main{display:none}</style><div>For full functionality of this site it is necessary to enable JavaScript. Here are the <a target="_blank" href="htxps://www.enable-javascript.com/">instructions how to enable JavaScript in your web browser</a>.</div></noscript></head><body><div id="contentMain"></div><script type="text/javascript" src="htxps://d1hi41nc56pmug.cloudfront.net/static/js/main.b55e5dfa.js"></script></body></html>
opening up to predictive response net via ->  hxtps://pipmegan.com/wp-content/plugins/mailchimp-for-wp/assets/js/forms-api.min.js?ver=4.3.3

Google Safe Browse checks have been performed on each of the linked sites. Links with poor reputation could be a threat to users of the site. Hosting and location are also included in the results.

Externally Linked Host           Hosting Provider   Country   
 -www.enable-javascript.com   Avalon d.o.o.           Croatia

pol
« Last Edit: May 25, 2020, 09:52:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!