Author Topic: HTML:Iframe-inf  (Read 6448 times)

0 Members and 1 Guest are viewing this topic.

gimmeshelter

  • Guest
HTML:Iframe-inf
« on: January 08, 2011, 07:59:53 PM »
Greetings -
Got the malware blocked message while trying to access the site hxxp://moviemaker.com. Tried to contact the webmaster, buy unfortunately I can't get to the website at all!  Ideas?  Suggestions? 

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
« Last Edit: January 08, 2011, 08:48:52 PM by Pondus »

spg SCOTT

  • Guest
Re: HTML:Iframe-inf
« Reply #2 on: January 08, 2011, 09:04:38 PM »
Hi gimmeshelter, welcome to the forum :)

avast! seems to be alerting on an iframe on the site which appears to be there about 7 times.

This iframe appears at the end of a very long one line script.

Scott


Offline danny96

  • Malware Fighter
  • Advanced Poster
  • **
  • Posts: 668
  • No-malware!
Re: HTML:Iframe-inf
« Reply #3 on: January 08, 2011, 09:32:39 PM »
i think that it's FP. Becauses Virustotal shows only 3 objects founded by Avast engine.
Real-time protection and Firewall: COMODO Internet Security 12.0.0.6810 -- Additional Protection: Web Of Trust, Ublock, NoScript, Malwarebytes Premium, Avast! Online Security, Hitman Pro -- OS: Windows 10

spg SCOTT

  • Guest
Re: HTML:Iframe-inf
« Reply #4 on: January 08, 2011, 09:38:44 PM »
i think that it's FP. Becauses Virustotal shows only 3 objects founded by Avast engine.
The site in the iframe:
http://www.google.com/safebrowsing/diagnostic?site=fragisdown.com/in.cgi%3F13

Whether it is a false positive or not I don't know...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: HTML:Iframe-inf
« Reply #5 on: January 08, 2011, 10:40:28 PM »
I have no doubt that this site has been hacked, as the site that the iframe tries to connect to as Scott mentions has been the subject of previous malware and browser exploits. Firefox safe browsing alerts on this site if you try to connect, image1 as does avast image2.

So the target site of the iframe still contains malware.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: HTML:Iframe-inf
« Reply #6 on: January 08, 2011, 10:50:52 PM »
Thanks David :)

One thing, snagit? ???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: HTML:Iframe-inf
« Reply #7 on: January 08, 2011, 11:06:19 PM »
For some reason avast doesn't like it when snagging the image of the firefox alert, why I don't know, it didn't used to do that with earlier avast versions.

Snagit 9.1, 1Click, Active Window ;D an absolute doddle.

I haven't been tempted with the upgrade to version 10, I think $24.95 (I think is too much for an update). There is still so much that I don't use in 9.1 I could probably stuck with snagit 6 which I think I started off with.
« Last Edit: January 08, 2011, 11:10:55 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: HTML:Iframe-inf
« Reply #8 on: January 08, 2011, 11:13:01 PM »
i think that it's FP. Becauses Virustotal shows only 3 objects founded by Avast engine.
The VBA32 engine on VirusTotal is still running 2011.01.06 update, but on NoVirusThanks it have 08/01/2011, so there will be one extra detection when updated

On Virscan it show suspicious detection with the old signatur
http://virscan.org/report/ef7245e9b6867d71ae43f8f0783d98b7.html

spg SCOTT

  • Guest
Re: HTML:Iframe-inf
« Reply #9 on: January 08, 2011, 11:16:18 PM »
Snagit 9.1, 1Click, Active Window ;D an absolute doddle.

I haven't been tempted with the upgrade to version 10, I think $24.95 (I think is too much for an update). There is still so much that I don't use in 9.1 I could probably stuck with snagit 6 which I think I started off with.

So using the capture active window feature causes an alert? :D
I have to try that with evernote...


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: HTML:Iframe-inf
« Reply #10 on: January 09, 2011, 01:07:51 AM »
Thinking back I don't think it will have been the active window (I just used that to capture the avast alert), the alert came after doing a region scan of the firefox alert.

I don't know what is going on with the web shield alerts since 5.1, but I no longer see any unp99999.tmp file in the _avast5_ folder that I would usually use for analysis.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: HTML:Iframe-inf
« Reply #11 on: January 09, 2011, 01:36:12 AM »
I don't know what is going on with the web shield alerts since 5.1, but I no longer see any unp99999.tmp file in the _avast5_ folder that I would usually use for analysis.

I don't use that method myself, but the _avast5_ folder never shows the tmp files, even if an alert is open now...wonder what changed? (though I suppose this is for another thread...)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: HTML:Iframe-inf
« Reply #12 on: January 09, 2011, 02:14:53 AM »
I don't know what is going on with the web shield alerts since 5.1, but I no longer see any unp99999.tmp file in the _avast5_ folder that I would usually use for analysis.

I don't use that method myself, but the _avast5_ folder never shows the tmp files, even if an alert is open now...wonder what changed? (though I suppose this is for another thread...)

Yes, perhaps that would be best.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline danny96

  • Malware Fighter
  • Advanced Poster
  • **
  • Posts: 668
  • No-malware!
Re: HTML:Iframe-inf
« Reply #13 on: January 09, 2011, 09:03:06 AM »
I have no doubt that this site has been hacked, as the site that the iframe tries to connect to as Scott mentions has been the subject of previous malware and browser exploits. Firefox safe browsing alerts on this site if you try to connect, image1 as does avast image2.

So the target site of the iframe still contains malware.
favicon.ico ???
This is the most infected image ever!
This is not FP. That image is dangerous!
Real-time protection and Firewall: COMODO Internet Security 12.0.0.6810 -- Additional Protection: Web Of Trust, Ublock, NoScript, Malwarebytes Premium, Avast! Online Security, Hitman Pro -- OS: Windows 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: HTML:Iframe-inf
« Reply #14 on: January 09, 2011, 12:14:12 PM »
NORMAN analysis, say infected and will add detection

Quote
  moviemaker.com.htm : Processed - HTML/IFrame.HJ
« Last Edit: January 09, 2011, 12:23:00 PM by Pondus »