Avast does not detect Trojan.IframeRef on Ukrainian site...

See: htxps://www.virustotal.com/url/3e93bca27902ea75342578ed8a36bdc425829bbbcdccb270a220ec3830651a58/analysis/
Alll of the detection details here: hxtp://sitecheck.sucuri.net/results/strojka-novostrojka.ru/
Hidden iFrame source hxtp://sv22 dot ru/l html malware = Trojan.IframeRef,
BirDefender TrafficLight flags this site as unsafe…

reported to virus AT avast dot com,

polonus

When trying for a GET request with WebBug for the hidden Iframe address, I get:

403 Forbidden
You do not have permission to access this document.

Web Server at altairegion dot com

  • Unfortunately, Microsoft has added a clever new
  • “feature” to Internet Explorer. If the text of
  • an error’s message is “too small”, specifically
  • less than 512 bytes, Internet Explorer returns
  • its own error message. You can turn that off,
  • but it’s pretty tricky to find switch called
  • “smart error messages”. That means, of course,
  • that short error messages are censored by default.
  • IIS always returns error messages that are long
  • enough to make Internet Explorer happy. The
  • workaround is pretty simple: pad the error
  • message with a big comment like this to push it
  • over the five hundred and twelve bytes minimum.
  • Of course, that’s exactly what you’re reading
  • right now.

Why they do that?

polonus

virustotal
https://www.virustotal.com/file/a9bf1e60c8a48ccc4135c329f52a061591bfc96f5c530818959409589366cc65/analysis/1338849411/

Hi Pondus,

Well funny that IE steps in there and shows it’s own error message: HTTP 404 if less than 512b and delivers “File not found Internet Explorer”,
while Fx for instance will not do that. The malversants made a mistake and did not make sure that code does not get executed when redirected.
A good indicator to easier detect this Trojan.IframeRef malcode, i.m.o.
By the way Cheating Iframe Detector by mvent2 extension in GoogleChrome also flags the hidden iFrame there,
and gives the source of it and the option to block it,

polonus