CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Geocities

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 63
Location: South Carolina, USA

PostPosted: Fri Dec 28, 2007 11:49 am    Post subject: Geocities
Reply with quote

maybe this has been posted before, but i ran across this site, today, in a spam-email:

hxxp://geocities.com/KelvinOdonnell

my antivirus program went crazy when i clicked the link..

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Fri Dec 28, 2007 3:59 pm    Post subject:
Reply with quote

can you be more specific?
what antivirus product are you using?

presumably it gave you a warning message?

it may even have identified the virus it thinks it found.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Fri Dec 28, 2007 4:03 pm    Post subject:
Reply with quote

The site uses code to redirect users to

Code:
http://swuyy.com/


which is currently down.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx


Last edited by tetak on Fri Dec 28, 2007 4:08 pm, edited 1 time in total
Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Fri Dec 28, 2007 4:06 pm    Post subject:
Reply with quote

I use avira antivirus, and it flags the page as having the "virus" named: HTML/Crypted.Gen

which is a generic term it uses any time it sees obfuscated javascript.

http://www.avira.com/en/threats/section/fulldetails/id_vir/3666/html_crypted.gen.html

Tetak is right, the page is only doing an obfuscated javascript redirect.

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 63
Location: South Carolina, USA

PostPosted: Fri Dec 28, 2007 6:44 pm    Post subject:
Reply with quote

i don't have a record, now, of the things that "antivir" flagged.. i had 10 individual antivir-alerts when i opened the webpage..

i went to the "linkscanner" website and had it scan the webpage.. i think that it reported that in had numerous issues, one of which was "warezov sploit" and something about a "get splice" vulnerability..

apparently, the webpage has been taken down, now..

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 63
Location: South Carolina, USA

PostPosted: Sat Dec 29, 2007 3:05 am    Post subject:
Reply with quote

tetak wrote:
The site uses code to redirect users to

Code:
http://swuyy.com/


yes, tetak, that was the reason that i clicked the geocities-link in the first place, because i figured that it redirected to some other webpage, and i wanted to report them, for "spam", which i did.. the "swuyy.com" webpage was not down, at the time..

apparently the geocities webpage IS up, now.. here is what "linkscanner" reports when it scans the geocities webpage:

DANGEROUS: LinkScanner Online has found
[Search engine hijack]

Detail: Exploit: Warezov sploit launcher
This is actually a new obfuscation of several common exploits, the newest being SetSlice, which, at the time of initial detection, was being used to install the Warezov worm on vulnerable systems.
Risk Category: Exploit

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 63
Location: South Carolina, USA

PostPosted: Sun Dec 30, 2007 8:11 pm    Post subject:
Reply with quote

i have been getting a lot of spam, lately, with links to other geocities webpages that seem to have the same "malware".. here is a link to the latest one that i got:

hxxp://geocities.com/SamSoto34

"linkscanner" says:

Exploit: Warezov sploit launcher
This is actually a new obfuscation of several common exploits, the newest being SetSlice, which, at the time of initial detection, was being used to install the Warezov worm on vulnerable systems.

i would like to know where the "warezov worm" is being downloaded from..

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Mon Dec 31, 2007 1:04 pm    Post subject:
Reply with quote

GeoCities have removed the site.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer