Author Topic: Another form of malicious google analytics redirect..  (Read 2070 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Another form of malicious google analytics redirect..
« on: June 19, 2010, 10:50:16 PM »
Hi malware fighters,

Injected malcode can redirect to bestgoogleanalytics*com

Domain Hash    ca7a0ec6d1295de5c5f782aa0aa1397d
IP Address    194.8.250.49
IP Hostname    -
IP Country    -- (--)
AS Number    43134
AS Name    COMPLIFE-AS CompLife Ltd
Detections    6 / 19 (32 %)
Status    DANGEROUS
    Last time suspicious content was found on this site was on 2010-06-19.

    Malicious software includes 105 scripting exploits

    This site was hosted on 2 network(s) including AS43134 (COMPLIFE), AS11798 (BLUEHOST).

Has this site acted as an intermediary resulting in further distribution of malware?

    Yes, bestgoogleanalytics.com appeared to function as an intermediary for the infection of 22 sites including fordstheatre.org/, therats.org/, seanbluestone.com/.

Has this site hosted malware?

    Yes, this site has hosted malicious software. It infected 9 domains, including stylenerds.com/, mimiblume.com/, seanbluestone.com/.

    In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message. You find here: Welcome to the home of Best Google Analyti...^img src="goog_e.gif"^etc.>

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!