Author Topic: Malicious site  (Read 8191 times)

0 Members and 1 Guest are viewing this topic.

avast_junkie

  • Guest
Malicious site
« on: October 10, 2009, 05:23:39 PM »
Hi i'm new here  ;D

I using avast! for almost 3 months and quite satisfied, i'm amazed with the speed of avast. Before that I use norton, kaspersky which makes my pc really slow.
Recently I visited the Indonesian website hxxp:\\www.d60pc.com (quite popular site) this site about freeware and tutorial.
When I visited the site, network shiled detects hxxp:\\www.d60pc.com as a malicious site, with norton or kaspersky, they not detect as malicious site
And i try pause the network shield, avast! showing popup like this


Both Norton & Kaspersky not found anything (tested with other PC)
After that I did a quick scan, but did not find any

Please the experts here can provide me some answer about that site is really dangerous or just false positive.

Thanks before

PS: Sorry for my english  ::)
« Last Edit: October 10, 2009, 05:33:18 PM by avast_junkie »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Malicious site
« Reply #1 on: October 10, 2009, 05:30:04 PM »
Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Maybe you could contact its webmaster.

Please, edit the links to not-live ones (change http for hxxp, for instance or add spaces between the url).

Hope Kubecj could check if the site is clean and if it is a false positive.
Welcome to avast forums ;)
The best things in life are free.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Malicious site
« Reply #2 on: October 10, 2009, 05:30:59 PM »
Network Shield blocks the domain, Web Shield finds a malware in the actual web... that certainly doesn't sound like a false positive.

Mr.Agent

  • Guest
Re: Malicious site
« Reply #3 on: October 10, 2009, 05:34:50 PM »
Strange result from here

http://wepawet.iseclab.org/view.php?hash=3afc56e4256a0eae396f3b38cfdcb7dc&t=1255189002&type=js

http://www.UnmaskParasites.com/security-report/?page=d60pc.com

He is very vunerable as i can see he didnt update so much his program... ;)

Mr.Agent
« Last Edit: October 10, 2009, 06:56:40 PM by Mr.Agent »

Mr.Agent

  • Guest
Re: Malicious site
« Reply #4 on: October 10, 2009, 05:36:49 PM »
Sorry for double post.

Also look the comments from HP Host http://www.mywot.com/en/scorecard/www.d60pc.com

This sound very strange for me.

avast_junkie

  • Guest
Re: Malicious site
« Reply #5 on: October 10, 2009, 05:52:01 PM »
Wow
Thx for fast replies, so the conclusion is that is contain malware
Only avast was able to detect it

Thx guys

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Malicious site
« Reply #6 on: October 10, 2009, 06:11:05 PM »
The main reason for the site to get infected is this : Warning: Old version of WordPress. It may be vulnerable. Please upgrade. you can see on the unmaskparasites webpage, you may ask the webmaster to update to latest version of the software and also change the password.

http://www.UnmaskParasites.com/security-report/?page=d60pc.com

nmb

Mr.Agent

  • Guest
Re: Malicious site
« Reply #7 on: October 10, 2009, 06:57:27 PM »
Exactly nmb i did also missed up my link of unmasked so i did edit mine. lol.

Still i did it first you are too late ;)

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Malicious site
« Reply #8 on: October 10, 2009, 07:16:10 PM »
more than the link, I wanted him to know the probable reason for the iframe injection as you can see in my post in bold letters.

nmb


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Malicious site
« Reply #9 on: October 10, 2009, 07:29:15 PM »
Hi avast_junkie,

While 23,500 new infected Web pages - one every 3.6 seconds - were detected each day during the first 6 months of this year. Read about the reasons of compromised sites here:
http://features.techworld.com/security/3201799/seven-reasons-websites-are-not-secure/?pn=1  and
http://features.techworld.com/security/3201799/seven-reasons-websites-are-not-secure/?pn=2
For the websites the reason is older vulnerable software used by hoster and/or webadmin: PHP, script exploits.
buggy older software. For online browser users not fully updated and patched OS and third party software (check with Secunia PSI).
Also read on Sanitizing code: http://ask.metafilter.com/70682/How-to-Sanitize-HTML-Javascript-Security
A first and only online diff tool: http://utilitymill.com/utility/Text_Diff

polonus
« Last Edit: October 10, 2009, 07:32:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

avast_junkie

  • Guest
Re: Malicious site
« Reply #10 on: October 11, 2009, 08:13:12 AM »
Hi avast_junkie,

While 23,500 new infected Web pages - one every 3.6 seconds - were detected each day during the first 6 months of this year. Read about the reasons of compromised sites here:
http://features.techworld.com/security/3201799/seven-reasons-websites-are-not-secure/?pn=1  and
http://features.techworld.com/security/3201799/seven-reasons-websites-are-not-secure/?pn=2
For the websites the reason is older vulnerable software used by hoster and/or webadmin: PHP, script exploits.
buggy older software. For online browser users not fully updated and patched OS and third party software (check with Secunia PSI).
Also read on Sanitizing code: http://ask.metafilter.com/70682/How-to-Sanitize-HTML-Javascript-Security
A first and only online diff tool: http://utilitymill.com/utility/Text_Diff

polonus


Thanks polonus, thats very clear now
May i ask once again this is a stupid qustion, why another well known AV can't find anything on that site.
How about hxxp://gf.wiretarget.com
http://www.mywot.com/en/scorecard/gf.wiretarget.com
http://www.unmaskparasites.com/security-report/?page=http%3A//gf.wiretarget.com

whether this is the right room for this question?  ???

YoKenny

  • Guest
Re: Malicious site
« Reply #11 on: October 11, 2009, 10:54:19 AM »
@avast_junkie

hxxp://gf.wiretarget.com has keygens and should be blocked
Code: [Select]
10/11/2009 4:46:45 AM SYSTEM 1960 Sign of "HTML:RedirBA-inf [Trj]" has been found in "hxxp://74.125.95.132/search?q=cache:Z8G7ndk0ySoJ:gf.wiretarget.com/+gf.wiretarget.com&cd=1&hl=en&ct=clnk&gl=ca\{gzip}" file.  

avast! protects you from infections but if you insist on looking for warez or cracked software then your system will become infected.

I liked Nasi Goreng when I was there:
http://images.google.ca/imgres?imgurl=http://unofficialcook.com/wp-content/uploads/2006/02/NasiGoreng.png&imgrefurl=http://unofficialcook.com/recipes/masakan-indonesia-nasi-goreng/&usg=__blF3WrvHZmJzSAKFgnFpszyu70o=&h=431&w=522&sz=308&hl=en&start=2&um=1&tbnid=aDNFLSvrQUdGsM:&tbnh=108&tbnw=131&prev=/images%3Fq%3Dnasi%2Bgoreng%2Bindonesia%26hl%3Den%26sa%3DX%26um%3D1
« Last Edit: October 11, 2009, 11:06:11 AM by YoKenny »

avast_junkie

  • Guest
Re: Malicious site
« Reply #12 on: October 11, 2009, 01:08:45 PM »
Nasi goreng ;D i love it too  :P
Sorry off topic