system
March 21, 2013, 8:38pm
1
It seems this site hasent been blacklisted by avast. I recently visited this website thinking it was part of kerbalspaceprogram.com however it seems to be a fan site. When looking into the securi site scan this website seems to have malware.
URL visited: kerbalspaceprogram.net/privacy-policy (DO NOT GO TO THIS ADDRESS…)
Affects: Unknown Site Host Affects: Bad plugin on wordpress http://labs.sucuri.net/db/malware/malware-entry-mwiframehd202
Malware type: iFrame injection Diagnosis: http://sitecheck.sucuri.net/results/www.kerbalspaceprogram.net/privacy-policy
Blacklist: Hasent been Blacklisted yet, This seems to be an injection into the wordpress site.
Virus Total Scan: Green https://www.virustotal.com/en-gb/url/448b52271d9c6555f309120eb511f54ca036569924bd3f9c366bcf4b69fef300/analysis/1363898822/
Additional Scans pointing towards possible phishing scam? http://www.phishtank.com/phish_detail.php?phish_id=1768044
Any help on detecting and clearing this up? In addition mods should note that a previous post i had has been put on hold for some strange reason
Thanks
OliPicard
Pondus
March 21, 2013, 8:46pm
2
edit your post and remove www from the link so it is not clickable
Pondus
March 21, 2013, 8:47pm
3
system
March 21, 2013, 8:48pm
4
Hi Pondus, Have done as you have requested. (Sorry about that.)
Pondus
March 21, 2013, 8:50pm
5
Thanks…then we avoid click accidents
system
March 21, 2013, 8:52pm
6
Should i run Mbam/CCleaner/Combofix/OTL? It may be time for Essexboy!
system
March 21, 2013, 8:53pm
7
should note that sucuri saw this as this type of signature. http://labs.sucuri.net/db/malware/malware-entry-mwiframehd202 MW:IFRAME:HD202
Pondus
March 21, 2013, 8:57pm
8
you may do that… AdwCleaner / Malwarebytes / OTL / aswMBR
you find the guide at top in this forum section
system
March 21, 2013, 9:02pm
9
Tracing site, Will post anything i can find. First site seems clean until you see its redirecting people to another bit.ly site It seems to be a middleman attack. http://www.phishtank.com/phish_detail.php?phish_id=1768044 note it seems this site may have just been infected. This isnt good.
system
March 21, 2013, 9:15pm
10
Running MBAM, shall post log, After that will run aswmbr
system
March 21, 2013, 9:52pm
12
Just tried to run ASWMBR however this poped up and refused to go away.
Also provided this link http://cima.security.comodo.com/report/5203462c9e1a600682aedf312e89f35cb1c7fe9b.htm
system
March 21, 2013, 9:55pm
13
Running OTL shall post log
system
March 21, 2013, 10:03pm
15
OTL log + extras log
Shall go ahead and scan ASWMBR now
Yep turn off comodo though
Consider this: http://www.blog.web6.org/adsense-plugin-wordpress-are-you-sure-it-is-safe/ (link article author = KIMI)
See
185: < !-- Google Ads Injected by Adsense-Insert - wXw.naeem.pk → < a href=“htXp://www.naeem.pk”> < /a> < iframe src=“http://wXw.naeem.pk/ai.html ” width=“0” height=“0” frameborder=“0” marginwidth=“0” marginheight=“0”> < / iframe > Suspicious. Reason: Detected hidden reference to external web resource.
Details: Detected hidden iframe tag to ‘naeem.pk’
polonus
system
March 21, 2013, 10:11pm
18
aswMBR log attached. Was able to mark it as a false postive. Not sure why it did that as it was disabled…
So far nothing untoward in those scans, Steam has some ports open for that site. But, again looks ok
system
March 21, 2013, 10:15pm
20
Hi Polonus, Glad to see you here! Yeah ive looked at the securi scan and it seems in the additional info tab to be redirecting people to a phishing site (which has just been indentified today.)
Am alittle worried to say the least.