JS:Redirector-DC

whats with this site:
religion-faith.com/gallery/category/4-lord-ganesha-wallpapers.html

Avast web shield is blocking it

JS-Redirector-DC

is it a FP???

i was just searching over google for lord ganesha photos its a shame on bad guys if the bad guys are really hiding malware behind this picture >:(

You’re the expert or so you profess, investigate it.

Google image searches have been poisoned for some considerable time.

Where is the fun in that David? :stuck_out_tongue:

There are 4 occurrences of a script that causes avast to alert.

This script deobfuscates to a script

I would say this is a correct detection.

http://wepawet.iseclab.org/view.php?hash=eae8fccfe60520549d90199d6f1b4599&t=1323620237&type=js

http://www.virustotal.com/file-scan/report.html?id=d8e9b0e0a9f0ba87523358f0f58c18e3fdaa229a999e560ee036756e43fd68aa-1323619848

Many things could hide behind Ganesha! he’s a big elephant ;D

:wink:

+1 ;D 8)

Called 3 4 times.

Notepad++ says 4…either way, it deobfuscates to an script

Hi true indian,
This site has a lot of कली युग content, i.e. Kali-Yuga content,
To begin with it is a known phishing site,
look here for that domain, same IP: old-versions.net -ns21.ethii.com => 75.126.219.187
-ns22.ethii.com => 75.126.147.248
(AS36351) SOFTLAYER
74.86.226.13 Adware 2011-11-16

Going ro the actual website, there this part of the code is suspicious:
See: http://www.google.com/safebrowsing/diagnostic?site=AS:36351

Re: http://www.cidr-report.org/cgi-bin/as-report?as=AS36351&view=2.0
AS Name: SOFTLAYER - SoftLayer Technologies Inc.
IPs allocated: 975872
Blacklisted URLs: 5874

Hosts…
…malicious URLs? Yes
…badware? Yes
…botnet C&C servers? Yes
…exploit servers? No
…Zeus botnet servers? Yes
…Current Events? Yes

-religion-faith.com/media/system/js/modal.js suspicious
[suspicious:2] (ipaddr:74.86.226.13) (script) -religion-faith.com/media/system/js/modal.js
status: (referer=-religion-faith.com/gallery/category/4-lord-ganesha-wallpapers.html)saved 10588 bytes 9ebb50f3b85cf4a67bc003dcc419c505dc46906b
info: [decodingLevel=0] found JavaScript
error: undefined variable Class
error: undefined variable $extend
error: undefined variable Events
suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
Web rep: http://www.webutation.net/go/review/religion-faith.com
http://www.mywot.com/en/scorecard/
Bitdefenders TraddicLight stops us from going there: http://trafficlight.bitdefender.com/info?url=http%3A%2F%2Freligion-faith.com%2Fgallery%2Fcategory%2F4-lord-ganesha-wallpapers.html&language=en_US
This is what is found there and what avast also flags: http://www.virustotal.com/file-scan/report.html?id=9cf6b4d0e404aade9501ddd1f9d95a47e5911f33ab44920309b990dd3087542f-1323621249
See als suspicious here: http://wepawet.iseclab.org/view.php?hash=eae8fccfe60520549d90199d6f1b4599&t=1323621649&type=js
The redirect to http://1parlo.serveirc.com/ (does not respond) was found here:
-http://proxy.rkc-74.ru/2.cgi/2011/3/imc48
redirects to http://www.phoca.cz/phocagallery last had malware reported on 2011-12-0,

That’s all for now,

polonus

Many things could hide behind Ganesha! he's a big elephant ;D

Thats not funny craigh >:(

he is a god and the god who has a big heart…and this god is my favourite :slight_smile:

I know david that u are giving me back for what i did…but as i said i extremely apologise for that serious mistake and take it from me from now on no further such posts…

i understand why u guys made this rule…so i am sorry! :-[