Hi, i need somebody to analyze this website for me: hxxp://www.radiosoure.com.pt/
Avast 6.0.989 with vps11221-1 says this is infected HTML:Script-inf. This is the website of the most popular radio in my home town in Portugal and i need to know is this site is really compromised or not so i can warn then. Thank’s for any help you guys can give.
Sucuri scanner say infected, see attachment
Thank you Pondus. I warned then already by email, let’s hope they do something about it.
Norman analysis
The html Page has a href link Scripts/AC_RunActiveContent.js which connects to magnoliamails.com which has a history of malware and spam. Detection added - radiosoure.com.pt.htm : Processed - HTML/Agent.HV
Also urlvoid says that this site is clean.
For the malware see: http://sucuri.net/malware/malware-entry-mwjs150
malware redirect to: htxp://magnoliamails.com/_vti_bin/eaccelerator.php ></script>
This is a gumblar zombie URL - see: http://malware.im/list-of-gumblar-zombie-urls/ and
http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/
e.g. nr. 388 magnoliamails dot com/ _vti_bin/eaccelerator.php
For the Honeywales malicious site location check, see: http://honeywhales.com/kml/2009-11-17.kml
hxtp://magnoliamails.com/pages/index.php?refid= has a bad reputation, so I would not like to give the all green here,
polonus
Apparently the responded to my message in their Facebook page but they can’t find anything ???.
I gave then the link to this post to see if they contact us here too, their Facebook page is: https://www.facebook.com/profile.php?id=100001512627938 for anyone interested in contacting then there.