Author Topic: Still Win32:Spyware-gen [Spy] detected here?  (Read 1039 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Still Win32:Spyware-gen [Spy] detected here?
« on: July 12, 2016, 12:14:47 AM »
See: https://www.virustotal.com/en/url/474a858b7fe42de153b379f1cfdf7d244e33d37b6736b7314770c610f9e5d667/analysis/1468273973/
See: https://sitecheck.sucuri.net/results/kubita.at   blacklisted on https://www.yandex.com/infected?url=kubita.at&l10n=en
See: https://asafaweb.com/Scan?Url=kubita.at%2Fstart.htm
See: https://www.virustotal.com/en/ip-address/81.31.128.165/information/
Get no AOS warning on the site, nor from Bitdefender's: http://toolbar.netcraft.com/site_report?url=http://kubita.at
Nameserver certificate isues: backbone.co.at

Please contact the Certificate Authority for further verification.
Warnings
RC4
This server uses the RC4 cipher algorithm which is not secure. Disable the RC4 cipher suite and update the server software to support the Advanced Encryption Standard (AES) cipher algorithm. Contact your web server vendor for assistance.
SSLv3
This server uses the SSLv3 protocol which is not secure. Disable the SSLv3 protocol and enable a higher protocol version. Contact your web server vendor for assistance.
This server is vulnerable to:
Poodle (SSLv3)
This server is vulnerable to a Poodle (SSLv3) attack. If you have not disabled SSLv3 fallback support, disable it now and use TLS 1.2 or higher.
Info
BEAST
The BEAST attack is not mitigated on this server.
Certificate information
This server uses a Domain Validated (DV) certificate. No information about the site owner has been validated. Data is protected, but exchanging personal or financial information is not recommended.
Common name:
 -backbone.co.at
SAN:
 -backbone.co.at, -www.backbone.co.at
Valid from:
 2016-May-30 12:24:00 GMT
Valid to:
 2016-Aug-28 12:24:00 GMT
Certificate status:
 Valid
Revocation check method:
 OCSP
Organization:
 
Organizational unit:
 
City/locality:
 
State/province:
 
Country:
 
Certificate Transparency:
 Not embedded in certificate
Serial number:
 34abfd13324f509c01bb3a4242c79adb639
Algorithm type:
 SHA256withRSA
Key size:
 2048
Certificate chainShow details
Let's Encrypt Authority X3Intermediate certificate
-backbone.co.atTested certificate

Also consider: http://www.malwareurl.com/ns_listing.php?as=AS29654

Furthermore 3 problems here: https://mxtoolbox.com/domain/kubita.at/

polonus
« Last Edit: July 12, 2016, 12:21:13 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!