system
June 27, 2012, 6:34am
1
I am not too sure…i was searching off on google and got to a link from some site to hxtp://www.couponso.net/?subid=178775&subid2=191461
and this was blocked by avast network shield
Is this a FP ??? i love modern warfare games…
Nothing showed up on VT…
Pondus
June 27, 2012, 6:40am
2
You should know the drill…
More info…what does the avast warning say…screenshot?
Have you tested the url with sucuri and zulu…urlquery
system
June 27, 2012, 6:54am
3
Pondus
June 27, 2012, 7:28am
4
system
June 27, 2012, 7:39am
5
looks like a phishing attempt :-X
Thanks!..also i didnt notice the red alert by WOT see: http://www.mywot.com/en/scorecard/www.couponso.net
Pondus
June 27, 2012, 8:10am
6
also see the list of IP warnings at the bottom here
http://urlvoid.com/scan/couponso.net/
system
June 27, 2012, 8:23am
7
Thanks! that does seem malicious
Hi Pondus & true indian,
Verdict simple not malicious as such but functioning as a known scam website.
There is also a script that is going to clients dot bluecava.com/data?p=D440F31E-EDE7-4BB2-B328-527A10AB7572 …
with a n accompanying promotional iPad gift scam with an IMG SRC lander script …
Mentioned in the malicious hidden 0-0-0 iFrames here by Sucuri’s: http://sitecheck.sucuri.net/results/www.couponso.net/
bluecava dot com is known for unknown_html_RFI_eval malcode (most of the malware from that IP, 216.23.166.114, has been closed or is dead now),
but as a scam site still active and flagged. See: http://www.mywot.com/en/scorecard/clients.bluecava.com?utm_source=addon&utm_content=popup-donuts
Main site is flagged here for security issues: http://www.siteadvisor.com/sites/couponso.net
I reported site as scam site at zulu zscaler feed-back,
polonus
system
June 27, 2012, 11:06am
9
Nice explanation…thanks Pol
You can also use common sense.
Would a regular gaming site’s home page have a long string like subid=178775&subid2=191461 attached to it? Is it common to have an official game with the .net domain?
Compare to MW3:
callofduty.com/mw3/
couponso.net/?subid=178775&subid2=191461