Is this forum infected with malware?

Today I was searching stuff about a Batman comic and trought Google image search I got into forum named “nintenbrony.forumotion.com” and I didn’t seem to get anything weird when visiting the site, but I was a bit curious and decided to check it with few online url scanners (Virustotal, Norton, Mcfree Siteadvisor etc.), but only Sucuri handed me an information that the website was infected with malware (which is little weird since in Virustotal Sucuri SiteCheck also showed that the link was safe) and also on Siteadvisor some malware was seemingly reported by few of the commenters. Can anyone say anything to this?

I use Adblock and Noscript with Avast Online Security on Firefox.

https://sitecheck.sucuri.net/results/nintenbrony.forumotion.com
https://www.virustotal.com/fi/url/7ebdfdf9eb8eef803a79a53ec3cbd68425c0cb71180eb586561fda7db228bc94/analysis/

VirusTotal URL scan is a Blacklist check only, Sucuri website scanner will scan the URL for malware (and also blacklist check)

http://labs.sucuri.net/db/malware/malware-entry-mwblacklisted35

A suspicious code was identified loading content from a blacklisted domain.

seems the code is not malicious

html scan
https://www.virustotal.com/en/file/f212164ba66f21b26a800dd1ac9ba31bec54ab5ef6e7c14bbf9333c85dab4a1a/analysis/1443630841/

So could it be that Sucuri had some false positives? Thanks for clearivication. :smiley:

probably not …

Sucuri is saying A suspicious code was identified loading content from a blacklisted domain.

Sucuri does not say it is malicious

Probably ad`s loaded on that site and they are hosted at a blacklisted url

Apparently someone is not doing the job right at Google/Amazon Ashburn server racks,
because abuse is going on there as a potentially dangerous Request.Path value was detected from the client (<)

Well that code that is flagged by Sucuri’s is for Google Asynchronous Tracking Code
Read on issues: http://stackoverflow.com/questions/2538252/what-is-var-gaq-gaq-for
So I very much doubt this is malicious and might be a Sucuri’s misinterpretation of what the code does.

But there is more flagged through this scan report and even more serious requests going on:
See: https://urlquery.net/report.php?id=1443631601366
All either Google and/or Amazon related abuse.

Link to GET /cpush HTTP/1.1
Host: -rdcdn.com is flagged. Microsoft-IIS/8.0 Theresource can not be found at these Ashburn racks.
Two errors/fails and two warnings: https://asafaweb.com/Scan?Url=rdcdn.com
A potentially dangerous Request.Path value was detected from the client (<).
GET /ppt?v= HTTP/1.1
Host: -pxgp2.adpredictive.com is flagged, but service seems unavailable. *
http://toolbar.netcraft.com/site_report?url=http://pxgp2.adpredictive.com
GET /engine?site=133518;size=1x1;mimetype=img;du=56;csync=YgYkEJfWjF2S HTTP/1.1
Host: -pbid.pro-market.net is flagged! Google owned. → http://toolbar.netcraft.com/site_report?url=pbid.pro-market.net
ad-blocked: uMatrix has prevented the following page from loading:
-http://pbid.pro-market.net/
GET /contextmatch.php HTTP/1.1
Host: -ck.adohana.com is flagged! → http://toolbar.netcraft.com/site_report?url=ck.adohana.com
Bad web rep: https://www.mywot.com/en/scorecard/ck.adohana.com?utm_source=addon&utm_content=rw-viewsc

See this report: http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Fnintenbrony.forumotion.com%2Fportal&useragent=Fetch+useragent&accept_encoding=

polonus (volunteer website security analyst and website error-hunter)

From this you see the misconfiguration at the server with the potentially dangerous request detected.
This should never be returned:

This excessive error-info proliferation is to the world and attackers. With this server properly secured this sensitive information would not be spread.

polonus

Pardon my not perfect english/script coding understanding skills, but didn’t really manage to catch on what polonus ment. :-[

Hi Pernaman,

The technical details of this may go over your head a bit, but there are certainly folks here that understand what I mean to say. What I meant is that that the forum website seems OK, but external links are hosted on servers where to say it politely IT staff did not do an oustanding job. Error-messages from the server were returned spreading info that could mean insecurity. Everyone that has read the server manuals would have known what to do to have that server behave properly.
With the right server configuration this info would never get out and would not mean a security issue.

To say it in a few words the forum website is not to blame, those that monitor or host it should do a better job.
We see this a lot to-day because owners are no longer willing to pay IT staff decently and then you are left with incompetence (and insecurity). Sign of the times.

polonus

Thanks for explaining the subject a bit further.

I did some research of my own and on McFree Siteadvisor there were comments on how other sites under forumotion.com seemed to have some identical results from Sucuri having “malware-entry-mwblacklisted35”. Here’s also some little user comments from SiteAdvisor: https://www.siteadvisor.com/sites/msgpage/page1/nintenbrony.forumotion.com

I hope we can get some clarification from this soon. I’m off to bed now.

EDIT: https://sitecheck.sucuri.net/results/gameraterz.forumotion.com/

Hi Pernaman,

Have a good night’s rest. Yes they certainly should ask those at Amazon/Google that keep these websites in the air partly via their data centers to monitor what is going on, I could trace part of it back as far as I could see here to some racks in Ashburn Data Center Virginia - but as I have it right, we see an awful lot of click-traffic coming from that place and they had a fire January last, so the circumstances weren’t that ideal either, but that is no excuse for sloppy service. They should come up with some answers.

polonus

Reply from F-Secure lab

============================
Clean nothing malicious found.

Hi Pondus,

That makes sense as that script flagged by Sucuri’s is not malicious as such:
var-gaq-gaq-Google Asynchronous Tracking Code.

I said that already earlier, all I am left with is

Link to GET /cpush HTTP/1.1
Host: -rdcdn.com is flagged. Microsoft-IIS/8.0 Theresource can not be found at these Ashburn racks.
Two errors/fails and two warnings: https://asafaweb.com/Scan?Url=rdcdn.com
A potentially dangerous Request.Path value was detected from the client (<).
GET /ppt?v= HTTP/1.1
Host: -pxgp2.adpredictive.com is flagged, but service seems unavailable. *

If there was a threat out there, it is no longer available. What remains is the server misconfigurations found here:
Server: Microsoft-IIS/8.0 | X-Powered-By: Unknown | X-AspNet-Version: 4.0.30319 | X-AspNetMvc-Version: 4.0 | Web forms app: No | ASP.NET site: Yes | ASP.NET version: 4.0.30319.34212 | 5 requests were made by ASafaWeb:
URL Page title Response size Duration

  1. http://rdcdn.com/ The resource cannot be found. 3,181 bytes 14 ms
  2. http://rdcdn.com/trace.axd Trace Error 3,334 bytes 7 ms
  3. http://rdcdn.com/< A potentially dangerous Request.Path value was detected from the client (<). 3,809 bytes 5 ms
  4. http://rdcdn.com/elmah.axd 404 - File or directory not found. 1,245 bytes 2 ms
  5. http://rdcdn.com/elmah 403 - Forbidden: Access is denied. 1,233 bytes 29 ms
    12,802 bytes 57 ms
    Tracing: Pass Custom errors: Fail Stack trace: Fail Request validation: Not tested HTTP to HTTPS: Pass Hash dos patch: Pass ELMAH log: Pass Excessive headers: Warning HTTP only cookies: Pass Secure cookies: Pass Clickjacking: Warning View state MAC: Not tested

and all that does not need to influence that forum website.

What remains at that website is just what a normal adblocker would block also.

Naturally the folks at that Microsoft-IIS/8.0 server running linux should remedy that server’s misconfiguration(s) but that should not give head-aches to the victim. :wink:

Just added this: http://mxtoolbox.com/domain/rdcdn.com/ very contradictory to this report:
http://dnscheck.sidn.nl/?time=1443653355&id=1830765&view=basic&test=standard
HTTP 404. The resource you are looking for (or one of its dependencies) could have been removed, had its name changed, or is temporarily unavailable. Please review the following URL and make sure that it is spelled correctly.
http://toolbar.netcraft.com/site_report?url=http://rdcdn.com
HTTP Server: IIS 8.0
Operating System: Windows Server 2012
ASP.NET Version: 4.0.30319
Nameserver delegation error: http://dnscheck.sidn.nl/?time=1443653999&id=1830767&view=basic&test=standard
Delegation not found at parent.

polonus

So I guess we are clear then?

Probably, but I still get two suspicious items there,
One on a hidden iFrame scan:
Suspicious

');

and another on a Javascript check:
Suspicious

ata[ function at_adfillslot(){document.write(‘’);}//]]> </scrip…

This is for Promofly Discount coupons tool - not reported as malicious as such, could be adware?
http://toolbar.netcraft.com/site_report?url=http://delnapb.com

The remaining threat could be all that goes to -www.illiweb.com is flagged. I do not see it.

Re: http://www.rexswain.com/cgi-bin/httpview.cgi?url=http://www.forumotion.com/&uag=MSIE+8.0+Trident&ref=http://www.google.com&aen=&req=GET&ver=1.1&fmt=AUTO