DO NOT GO TO THIS URL! IT IS BROKEN TO AVOID HYPERLINK CREATION.
(Do not go there, it is malicious.)
Hi,
About 3 weeks ago I got this message saying the connection with soundartifacts.com was aborted. It was detected by Web Shield and the process was Google Chrome, my browser. What I want to know is what 8s this threat?!?
When I first opened the tab for soundartifacts.com, it was pretty much normal, didn’t look like a scam. After a few days or so, I tried to check VirusTotal. It said no engines detected the threat, even Avast! Maybe it has something to do with my local system. I am using Windows 11 Home. When I first went to that site, it said my internet connection was gone. When I tried to go to the control menu on the taskbar to check for Wi-Fi, the Wi-Fi icon was gone. Also, Avast kept saying Loading… after this. I booted again after a while to see the syste was fully functioning. The Wi-Fi tab is back again, Avast works, and everything else is working the way it should.
Frozen in fear, I quickly did a Full Scan and checked for virus definition updates. Everything was ok, and Avast said thee was no malware after the scan.
About a week before I checked VirusTotal, rescanned the website, and saw that one security vendor marked this as malicious. I still don’t know to this day what was wrong, but I guess it actually was malware.
/templates/content/js/share.js
Severity: Potentially Suspicious
Threat: PS.JS.Obfuscantion.gen
Reason: Detected obfuscated JavaScript code used to hide suspicious activity
Details: Detected procedure that is commonly used in suspicious activity.
Line: 1
Offset: 21442
Threat dump: View code - [p+“png/fd035XXXXXXXXXaa42adc8b87aa7791.png”} etc. (X by me, pol)
Threat dump MD5: F7923870AE5F3E2F3C64F36B18A10379
File size[byte]: 99793
File type: ASCII
Page/File MD5: DDB0BC034070D2D6741C7D1DE8049F81
Scan duration[sec]: 3.721
Read on this generic threat: https://www.f-secure.com/v-descs/trojan_js_obfuscated_gen.shtml
This generic detection identifies files (HTML, PDF JavaScript or scripts) that contain obfuscated code, which may be used by malware authors to evade detection by security products, or analysis by security researchers. (source: info as found on mentioned page).
Yes, the site check is prety weird since it says the domain was not found. This site is malicious, though. But the weird thing is when I visit it from mobile, it is not identified as a malware. So on mobile, it is fine, the site works as it should be.
Is there a possibillity that this may be a false positive?