Author Topic: Site blocked by Bitdefender's TrafficLight and WOT  (Read 1602 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Site blocked by Bitdefender's TrafficLight and WOT
« on: December 19, 2011, 06:47:14 PM »
Hi forum friends,

See: http://www.virustotal.com/url-scan/report.html?id=d09182012bf8e17663935471e5e2a437-1324304925
Up(nil):   unknown_html_RFI_php   RIPE   NL   karsten at -easyhosting.nl   81.26.219.44    to 81.26.219.44   -healingpraktijk-zijn.nl   -http://healingpraktijk-zijn.nl
and -www.healingpraktijk-zijn.nl/conny.html
See: http://urlquery.net/report.php?id=12584
I do not see anything particular towards the end of the caption.js and mootools.js code and
jsunpack is not alerting anything tgere. Could this have been cleansed in the meantime?

But there certainly is malware here: http://healingpraktijk-zijn.nl/report.pdf.exe
which is detected by avast as Win32:Malware-gen, see http://www.virustotal.com/file-scan/report.html?id=fd9f322cad37470f4ae40907e1945b2dbd2e613589430baaec803bb59071bc16-1324280815

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!