kvgr
-
Posts
7 -
Joined
-
Last visited
Kudos
-
-
kvgr gave kudos to Marcos in Website JS/Agent.rjr
You should be getting an alert like this:
The obfuscated JS responsible for loading this malicious script will be detected in 1-2 hours I assume.
-
kvgr gave kudos to itman in Website JS/Agent.rjr
Strange. I am not getting any alert, but Eset Web Filtering is detecting and blocking it;
Time;URL;Status;Detection;Application;User;IP address;Hash
2/5/2024 9:22:22 AM;https://near.flyspecialline.com;Blocked;Internal blacklist;C:\Program Files\Mozilla Firefox\firefox.exe;xxxxxxxx;2606:4700:3033::6815:4c11;ACC1CEC6D99C83F3D99BC4D0FEFC058D349CA731
-
kvgr gave kudos to Marcos in Website JS/Agent.rjr
That's expected cause we've blacklisted the site with the JS malware that was detected.
Now the new malware JS/Agent.RJZ trojan is detected on the main page as shown above.
-
kvgr gave kudos to itman in Website JS/Agent.rjr
The problem is I could fully access the web site w/o issue. No alert and no blocked access.
Correct. Alert now shown and web site access blocked.