system
4
Hello again! Sorry for topic lift, but I have something new which I think might fit with this.
I was doing some more Google search for recent possible Pixiv malware notices, and found a result link “times-pixiv.tumblr.com/”. I thought it would be a tumblr site, but when getting there it took me to “times.pixiv.net” which seemed like some sort of blog site for pixiv.net news. While visiting, I checked noscript list for the site, and saw for a glimpse of second one domain that dissappeared quickly. However, Noscripts list of recently blocked website managed to safe it. The blocked moain in it’s fullnes seemed to be “-cs600.wpc.edgecastdns.net”. I got to Google and got a link to Virustotal report of the domain that has some detections, but none for Avast or MBAM, only blacklists seem to come from Bitdefender. Sucuri and Virustotal show clean for times.pixiv.net itself.
https://sitecheck.sucuri.net/results/times.pixiv.net/
https://www.virustotal.com/en/url/633e100521e703c393f32f61d26579acb4daafbcdd3b927b58b0e5bc900fed8a/analysis/
Sucuri.net shows some scripts and iframes seemingly related to tumblr.com, compare to this:
https://sitecheck.sucuri.net/results/dawnlitroad.tumblr.com/
Here’s virustotal report for mentioned domain that Noscript blocked.
https://www.virustotal.com/en/domain/cs600.wpc.edgecastdns.net/information/