SeriousHoax 42 Posted April 22 Share Posted April 22 Hello! So, ESET detects a script loaded on this site: "https://tinyurl.is/AnVh?sport=soccer" and completely blocks me from accessing it. What type of script is this one and how dangerous is this? Kaspersky's analyst responded that the URL contains some links to sports site which are not malicious and the attached html file like this one: VirusTotal - File - 6b5d20a1e7ec6df5e6fe384cdf77add1c0dc9207dceb738c0106f13bba9750a4 doesn't contain any malicious code. Though it has quite a few detections on VT. Bitdefender added after my submission and seems to be a bad hash-based signature. Anyway, is it anything serious? Is there a way to make ESET block the script but still let me visit the website? I tried the found malware is ignored exception. It lets me visit the site, but ESET don't block anything on the site. Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,191 Posted April 22 Administrators Share Posted April 22 Hard to say what it does, it's heavily obfuscated. ESET is not the only AV to detect it. https://www.virustotal.com/gui/file/f039f277d215ea89643d6790eaf0c238e4ec93d98f5ac3727a060ce56f766fa6 Quote Link to comment Share on other sites More sharing options...
SeriousHoax 42 Posted April 22 Author Share Posted April 22 12 minutes ago, Marcos said: Hard to say what it does, it's heavily obfuscated. ESET is not the only AV to detect it. https://www.virustotal.com/gui/file/f039f277d215ea89643d6790eaf0c238e4ec93d98f5ac3727a060ce56f766fa6 Yeah, I have seen that too. Interesting. But as far as I know, none of these AV which has detected it has HTTPS scanning in their home product, so they won't detect the script in the browser like ESET. But anyway, as I asked, Is there a way to make ESET block the script on the site but still let me visit it? Quote Link to comment Share on other sites More sharing options...
itman 1,363 Posted April 22 Share Posted April 22 The domain is hosting SEOSpam malware. Refer to this Quttera report: https://quttera.com/detailed_report/tinyurl.is Quote Link to comment Share on other sites More sharing options...
SeriousHoax 42 Posted April 22 Author Share Posted April 22 5 minutes ago, itman said: The domain is hosting SEOSpam malware. Refer to this Quttera report: https://quttera.com/detailed_report/tinyurl.is Are these all loaded on their homepage? Quote Link to comment Share on other sites More sharing options...
itman 1,363 Posted April 22 Share Posted April 22 (edited) 3 hours ago, SeriousHoax said: Are these all loaded on their homepage? More likely something from one of the numerous JavaScript's running there. Quttera downloaded approx. 80 - 90 files that it analyzed. Edited April 22 by itman SeriousHoax 1 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.