Has this site now been cleansed?

Site is given at VirusWatch as with unknown malware, now given as clean…

See: http://siteinspector.comodo.com/public/reports/630598
See: http://vscan.urlvoid.com/analysis/9f8bd208ddf3a6ad5f58338c11ddda8b/bmV3c3Nob3ctYXNw/
Anubis analysis: http://anubis.iseclab.org/?action=result&task_id=19bd2ecb2e798b3847dffeb89b190bde7
Cryter Keylogger code and Trojan horse script code found: lsarpc, Flags: Named pipe ], Control Code: [ 0x0011C017 ] Iframe redirects to -http://user.free2.77169.net/vvv123/1.exe (Trojan Dropper file on program used for unlocking codes) But cannot be found according to jsunpack…
main site giving an “Under Construction”
DrWeb gives it as clean:
Checking: -http://viewbon.com/banner/wzjs.js?id=146
File size: 8624 bytes
File MD5: 70c6cf53bfa51ebb7c41489fcdf160b5

-http://viewbon.com/banner/wzjs.js?id=146 - Ok

Checking: -http://viewbon.com/newsshow.asp?id=146
Engine version: 5.0.2.3300
Total virus-finding records: 2797688
File size: 5061 bytes
File MD5: 098fe2615b417a03fd2d8170b35d5492

-http://viewbon.com/newsshow.asp?id=146 - Ok

polonus

I checked the site’s HTML coding by hand. Things I find suspicious are below. I didn’t check any sites that the site directed to, though.

I don’t think it’s clean, as the virus exe you mention is still there.

Link to the virus is dead.

The redirect link is dead…and

viewbon.com/banner/wzjs.js?id=146
http://virusscan.jotti.org/en/scanresult/10adac25d28230f056062325dedfb1a732b0f944

viewbon.com/newsshow.asp?id=146 - INFECTED
http://virusscan.jotti.org/en/scanresult/298a94fe56676a8a83253cd43790082064d011aa

Hi Pondus,

What Sophos detects through that second link is being described by them here: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Mal~Iframe-F/detailed-analysis.aspx

polonus

see another typical infected site:

paintball2.by.ru

Yet! not detected by avast! :cry:

viewbon.com/newsshow.asp?id=146 - INFECTED http://virusscan.jotti.org/en/scanresult/298a94fe56676a8a83253cd43790082064d011aa

Norman lab confirms infection

newsshow.asp : Processed - HTML/Iframe.PK

@Pondus a.o.

Again, Pondus, thanks for checking and the Norman lab analysis. I cannot see why this is not done by others and professionals more meticulously, but I haven’t heard anything about these issues yet ??? :smiley:
When I check on a particular URL scanner and later skim the actual code, I see a lot of discrepancy between the results we want to see and what we get. Each scanner equals their databases and some databases are outdated or rather “lousy”. There are some that are getting better and better.
We need to go through a lot of scanners, the one with a bit more reliable results than the other. Webreputation scan results and results based on recent blacklisting are hopeless almost because one never knows if the malware link is still up or down (nil) or the infested redirect or obfuscation is still there but is leading nowhere. URL scanning for a binairy analysis of what is at a particular URL gives better results, however if results are being correctly interpreted.
This all is making the task of taking out the “dirt” out of URL scanning even harder than it already is. Good we have been building such an expertise over the recent half year period since we started doing this, actually when I found that Pondus and Asyn were into this…

Thanks to DavidR for all his appropriate advice towards the way results were to be presented.

Thanks also to you, Asyn, Dim@rik, others and recently the young Donovansrb10 for investing into this line of specific virus hunting and unmasking malicious URLs. We also cannot give all our resources out here and have to make our results anonymous to certain degrees and present them as worked on images of scan results found, because we know also the malcreants are looking over our shoulders to establish what we detect about the activities of these never to be underestimated opponents. Thanks to all of my forum friends that helped towards a better detection scheme,

polonus

Hi true indian,

It had been better if you had posted about -paintball2.by.ru starting another thread.
That is now also no longer needed, because we are protected from going there because the avast webshield neatly blocks this site as infected through JS:Redirector-LS[Trj]
Do you have both webshield and network shield installed. They are top of the bill added security components of the avast av solution. We cannot feel secure without them active.
By the way DrWeb’s URL checker also detects:

Checking: -http://paintball2.by.ru
Engine version: 5.0.2.3300
Total virus-finding records: 2799714
File size: 6538 bytes
File MD5: fdf592126d7cca150ac6564122d8f049

-http://paintball2.by.ru - archive HTML

-http://paintball2.by.ru/Script.0 infected with JS.IFrame.140

polonus

thanks polonus i see it now ;D :

http://www.virustotal.com/file-scan/report.html?id=79f63c0da8fe6c841ff52eaaa8d474c0a6b9b370912da3c1731ff1a904ae34cf-1321694196