Author Topic: JS:Bulered  (Read 23675 times)

0 Members and 1 Guest are viewing this topic.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89202
  • No support PMs thanks
Re: JS:Bulered
« Reply #30 on: July 20, 2009, 09:53:28 PM »
The problem with obfuscated javascript it isn't easy to see what is being done much less if it is redirecting and to where as the image example of the code on that page I posted earlier.

I have no tools to be able to do any analysis (I like the others trying to help are just avast users like yourself), but given the link polonous gave (in the quoted text) you can do as you have and look-up the domains and as you have found they are considered malicious. So there is a likelihood that avast too finds these malicious and effectively alerts to block access.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: JS:Bulered
« Reply #31 on: July 20, 2009, 09:55:58 PM »
Hi Filter,

Yep, good observation, this is what google has to say about exist dot butterflyeffect dot gs and that was "De vorige keer dat verdachte inhoud op deze site werd aangetroffen (last time suspicious content was found), was op (was on) 2009-07-20. Malicious software includes 96 scripting exploit(s). This site was hosted on 1 network(s) including AS31103 (Keyweb AG).
The other one: ipot dot applepie dot gd forward slash privatezone Last time suspicious content was found on this site was on 2009-07-20
De vorige keer dat verdachte inhoud op deze site werd aangetroffen, was op 2009-07-20.
Malicious software includes 754 scripting exploit(s).
This site was hosted on 2 network(s) including AS41062 (PRO100), AS22576 (LAYER3).
Deze site heeft in de afgelopen 90 dagen schadelijke software gehost. Deze software heeft 361 domein(en) geïnfecteerd, waaronder xvediox.com/, flashost.com.br/, coralhillsresort.com/.
This site has been hosting malcode during the last 90 day period. This software has been infected 361 domains, e.g. :  xvediox.com/, flashost.com.br/, coralhillsresort.com/.
Just delving a little into this and you see what we come up with. Easy answers won't do, confront them with this - what does the obfuscated code do on that web page?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Filter

  • Guest
Re: JS:Bulered
« Reply #32 on: July 20, 2009, 10:02:04 PM »
Thanks, both of you. This should be more than enough evidence.  ;)

Have to say that I came to understand alot more about JS:Bulered ;D
« Last Edit: July 20, 2009, 10:06:07 PM by Filter »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89202
  • No support PMs thanks
Re: JS:Bulered
« Reply #33 on: July 20, 2009, 10:13:43 PM »
You're welcome, good luck.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: JS:Bulered
« Reply #34 on: July 20, 2009, 10:16:50 PM »
Ha Filter,

Het genoegen was wederzijds, wij leren hier ook weer van. Je begrijpt dat dit recentelijk steeds belangrijker aan het worden is omdat CyberCrook & Co het nu via deze listigheidjes voorzien heeft op de betrouwbare kleinere websites, die hier niet zo op verdacht zijn. Avast heeft hier speerpunt technologie en de avast schilden werken goed. Ook is het altijd verstandig een browser met script blocker te gebruiken, ik zweer bij Firefox met NoScript. NoScript is nog geen enkele keer verslagen als je de malcode maar niet whitelist en daarom is het besmetten van normaliter betrouwbare veilige sites zo'n gevaarlijke zaak. Welkom op onze forums, blijf hier komen met je vragen en blijf ons inspireren. Ik wens je veiligheid online en blijf malware vrij,

polonus aka Damiaan
« Last Edit: July 20, 2009, 10:18:41 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Filter

  • Guest
Re: JS:Bulered
« Reply #35 on: July 20, 2009, 10:25:16 PM »
Bedankt. Ben al heel lang blij met Avast :) Ik blijf hier zeker rondhangen!

scurrminator

  • Guest
Re: JS:Bulered
« Reply #36 on: August 04, 2009, 08:57:26 PM »
hello guys,

i am having the same issue, my site is getting hacked again and again, i always remove the same malicious code from my phpbb3, coppermine, wordpress and the static web pages one by one but its there again after a day or two, contacted my webhosting company but they dont have any solution, my avast antivirus used to tell me that i have some JS:Bulered virus in my pages but i used to ignore till i started getting this on my website hXXp://www.intcube.com though my cpanel was never hacked and i am still able to use it, saw a few posts in the avast forums and some others aswell but no one knows about the exact nature of this malware

Quote
http://www.hackthissite.org/forums/viewtopic.php?f=29&t=3849!
http://forum.avast.com/index.php?topic=46176.0
http://forum.avast.com/index.php?topic=46919.0



after going through google advisory pages, i changed my password after cleaning pages from various computers but whenever i would logon my pages would again be infected with the code mentioned above, google says



i checked lemonia.ws google advisory pages and it clearly shows that its the source of virus,



in june there was nothing regarding js:bulered malware in google search, but now we're having alot of forums where people are discussing this, think its spreading more and more and may be some one would help us too, can any one suggest what should i do?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Bulered
« Reply #37 on: August 04, 2009, 09:07:34 PM »
Please, do not post twice the same. Just double the effort of helping.
Follow http://forum.avast.com/index.php?topic=46176.0;topicseen
The best things in life are free.