Author Topic: What unknown html malware is here?  (Read 1293 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
What unknown html malware is here?
« on: March 24, 2012, 05:27:20 PM »
Nothing found here: htxp://vscan.urlvoid.com/analysis/683cedc4ca1ce2b6e672285a907b8890/ZC1waHA=/
Given suspicious here: htxp://zulu.zscaler.com/submission/show/fc8f26b8d0111d45f3689660da9337ee-1332605303
This givens as suspicious decoded file: wXw.ok.net/ suspicious
[suspicious:2] (ipaddr:94.75.217.42) (jsvar) wXw.ok.net/
     status: (referer=xaterozi.co.tv/x11/d dot php?f=22)saved 43642 bytes b5ec8ac9b89979b282c0c8648bc6a5095ae3cbaa
ok dot net also flagged on scamwarners dot com, BrightCloud rep index yellow 49 Moderate Risk
There is some probability that the user will be exposed to malicious links or payloads.
Seems malware response has been closed as from: 2012-03-24 01:29:56
But still listed as Phishing site,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!