system
December 11, 2011, 4:14pm
1
whats with this site:
religion-faith.com/gallery/category/4-lord-ganesha-wallpapers.html
Avast web shield is blocking it
JS-Redirector-DC
is it a FP???
i was just searching over google for lord ganesha photos its a shame on bad guys if the bad guys are really hiding malware behind this picture >:(
DavidR
December 11, 2011, 4:25pm
2
You’re the expert or so you profess, investigate it.
Google image searches have been poisoned for some considerable time.
system
December 11, 2011, 4:28pm
3
Where is the fun in that David?
There are 4 occurrences of a script that causes avast to alert.
This script deobfuscates to a script
I would say this is a correct detection.
CraigB
December 11, 2011, 4:33pm
5
Many things could hide behind Ganesha! he’s a big elephant ;D
system
December 11, 2011, 4:44pm
9
Notepad++ says 4…either way, it deobfuscates to an script
polonus
December 11, 2011, 4:58pm
10
Hi true indian,
This site has a lot of कली युग content, i.e. Kali-Yuga content,
To begin with it is a known phishing site,
look here for that domain, same IP: old-versions.net -ns21.ethii.com => 75.126.219.187
-ns22.ethii.com => 75.126.147.248
(AS36351) SOFTLAYER
74.86.226.13 Adware 2011-11-16
Going ro the actual website, there this part of the code is suspicious:
See: http://www.google.com/safebrowsing/diagnostic?site=AS:36351
Re: http://www.cidr-report.org/cgi-bin/as-report?as=AS36351&view=2.0
AS Name: SOFTLAYER - SoftLayer Technologies Inc.
IPs allocated: 975872
Blacklisted URLs: 5874
Hosts…
…malicious URLs? Yes
…badware? Yes
…botnet C&C servers? Yes
…exploit servers? No
…Zeus botnet servers? Yes
…Current Events? Yes
-religion-faith.com/media/system/js/modal.js suspicious
[suspicious:2] (ipaddr:74.86.226.13) (script) -religion-faith.com/media/system/js/modal.js
status: (referer=-religion-faith.com/gallery/category/4-lord-ganesha-wallpapers.html )saved 10588 bytes 9ebb50f3b85cf4a67bc003dcc419c505dc46906b
info: [decodingLevel=0] found JavaScript
error: undefined variable Class
error: undefined variable $extend
error: undefined variable Events
suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
Web rep: http://www.webutation.net/go/review/religion-faith.com
http://www.mywot.com/en/scorecard/
Bitdefenders TraddicLight stops us from going there: http://trafficlight.bitdefender.com/info?url=http%3A%2F%2Freligion-faith.com%2Fgallery%2Fcategory%2F4-lord-ganesha-wallpapers.html&language=en_US
This is what is found there and what avast also flags: http://www.virustotal.com/file-scan/report.html?id=9cf6b4d0e404aade9501ddd1f9d95a47e5911f33ab44920309b990dd3087542f-1323621249
See als suspicious here: http://wepawet.iseclab.org/view.php?hash=eae8fccfe60520549d90199d6f1b4599&t=1323621649&type=js
The redirect to http://1parlo.serveirc.com/ (does not respond) was found here:
-http://proxy.rkc-74.ru/2.cgi/2011/3/imc48
redirects to http://www.phoca.cz/phocagallery last had malware reported on 2011-12-0,
That’s all for now,
polonus
system
December 12, 2011, 11:48am
11
Many things could hide behind Ganesha! he's a big elephant ;D
Thats not funny craigh >:(
he is a god and the god who has a big heart…and this god is my favourite
system
December 12, 2011, 11:51am
12
You’re the expert or so you profess, investigate it.
Google image searches have been poisoned for some considerable time.
I know david that u are giving me back for what i did…but as i said i extremely apologise for that serious mistake and take it from me from now on no further such posts…
i understand why u guys made this rule…so i am sorry! :-[