Help | Contact Us
NukeWorker.com
NukeWorker Menu So What Is This? honeypot

Author Topic: So What Is This?  (Read 72238 times)

0 Members and 1 Guest are viewing this topic.

Fermi2

  • Guest
So What Is This?
« on: Sep 06, 2012, 07:31 »
http://therlade.pro/ir040xzxwug/

My anti virus program is picking this up when I try opening nukeworker. It was blocking nukeworker completely so I turned Webshield off. When Nukeworker opened the antivirus program blocked the above...

drayer54

  • Guest
Re: So What Is This?
« Reply #1 on: Sep 06, 2012, 08:41 »
I've had similar issues and can't access the site from certain networks. I get an antivirus warning and denied completely.

Offline HydroDave63

  • Retired
  • *
  • Posts: 6293
  • Karma: 6629
Re: So What Is This?
« Reply #2 on: Sep 06, 2012, 10:02 »
http://health.phys.iit.edu/archives/2012-July/036665.html

Some fellow at CDC got the malware warning July 10th.

Offline Marlin

  • Forum Staff
  • *
  • Posts: 18133
  • Karma: 5147
  • Gender: Male
  • Stop Global Whining!!!
Re: So What Is This?
« Reply #3 on: Sep 06, 2012, 10:16 »
I am having the same problem, it comes and goes so I just try periodically until it lets me in. I have no problem entering PolySci just the main board.

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #4 on: Sep 07, 2012, 02:27 »
I appreciate the reports. I'm looking into it.  We have a lot of complex software, and it's not always easy to figure out what those hackers have messed up.

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #5 on: Sep 07, 2012, 03:11 »
I'm hunting and deleting and removing... let me know if you stop getting the warnings.  Also, any details you can provide, especially if it can tell me what files to look at.

Fermi2

  • Guest
Re: So What Is This?
« Reply #6 on: Sep 07, 2012, 11:23 »
Mine denied me for 3 days. Avast has an option where you can exclude sites from it's Webshield. I tried excluding but it wouldn't let me in. So I turned Web Shield off. It let Nukeworker on because that was the url I was trying to get into but it stopped that thing I just posted.

I haven't tried logging on at home again.

Mike it didn't give a folder or file, it only gave me what I posted here.

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #7 on: Sep 07, 2012, 02:27 »
Best as I can tell AVG claims we have the "Phoenix exploit kit" on 16 Pages, but it wont mention what 16 they are.  Could be a false positive.

I scanned the site with 30 others scanners (including Google Safe Browsing), and they all came up clean... only AVG 'thinks' we have an issue.

http://scanurl.net/?u=http%3A%2F%2Fwww.nukeworker.com&uesb=Check+This+URL#results
http://siteinspector.comodo.com/public/reports/5738151
https://www.virustotal.com/url/02254d6374e5fa6788547a79fe2f7e822a3834d7c5e606c275bc24aa91856b1d/analysis/1347041852/
http://online2.drweb.com/cache/?i=4b6c193d8e6fa63daf0127948146d587
http://urlvoid.com/scan/nukeworker.com/
http://urlquery.net/report.php?id=166421
http://safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.nukeworker.com


I made a few minor changes anyways, let me know if you are still getting the warnings.

Honestly, if Google doesn't think we have an issue, and 30 other scanners think we are safe.... the problem may be with AVG trying to sell more software or something.  I've scanned the site with many virus scanners, and they find nothing.  AVG claims something is there, but wont say where it is specifically.  Very vague...
« Last Edit: Sep 07, 2012, 02:49 by Rennhack »

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #8 on: Sep 07, 2012, 02:53 »
I've see that kind of activity before when our site was clean, but the client side computer (yours) had a virus that redirected your website requests through bad websites.

I guess it's possible that AVG is the only software that can detect this really old virus threat, and the other 30 (including norton and google) can't.

Fermi2

  • Guest
Re: So What Is This?
« Reply #9 on: Sep 07, 2012, 10:39 »
From other computers I don't get banned or locked out. I don't have AVG, I have a free anti virus called Avast. So far they haven't tried selling me anything. I turned Avast Webshield off it let me in here but blocked that other site again.

drayer54

  • Guest
Re: So What Is This?
« Reply #10 on: Sep 08, 2012, 11:56 »
Mine just says Malware detected and blocks the site entirely. I've noticed this since last Tuesday.

Offline HydroDave63

  • Retired
  • *
  • Posts: 6293
  • Karma: 6629
Re: So What Is This?
« Reply #11 on: Sep 08, 2012, 01:11 »
An excellent description of the Phoenix exploit found here:

http://labs.m86security.com/tag/phoenix-exploit-kit-3-0/

Offline Marlin

  • Forum Staff
  • *
  • Posts: 18133
  • Karma: 5147
  • Gender: Male
  • Stop Global Whining!!!
Re: So What Is This?
« Reply #12 on: Sep 08, 2012, 01:36 »
An excellent description of the Phoenix exploit found here:

http://labs.m86security.com/tag/phoenix-exploit-kit-3-0/


Thanks HD I just had a WordPress site dumped on me and I am suffered vapor lock of the brain trying to come up to speed. I don't believe that Mike is using WordPress.

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #13 on: Sep 08, 2012, 01:43 »
Mine just says Malware detected and blocks the site entirely. I've noticed this since last Tuesday.

Does it STILL do that?
« Last Edit: Sep 09, 2012, 12:28 by Rennhack »

Offline HydroDave63

  • Retired
  • *
  • Posts: 6293
  • Karma: 6629
Re: So What Is This?
« Reply #14 on: Sep 08, 2012, 02:26 »
Thanks HD I just had a WordPress site dumped on me and I am suffered vapor lock of the brain trying to come up to speed. I don't believe that Mike is using WordPress.

My speculation is that UncaBuff is on an infected server in Kampuchea, and when he uploaded some pics it rode aboard, since the delivery method seems to be FTP. But I'm no coder.

Fermi2

  • Guest
Re: So What Is This?
« Reply #15 on: Sep 08, 2012, 11:51 »
Does it STILL to that?

In my case yes.

Offline HydroDave63

  • Retired
  • *
  • Posts: 6293
  • Karma: 6629
Re: So What Is This?
« Reply #16 on: Sep 09, 2012, 09:31 »
Anyone running XP needs to be especially careful, and update Java to Version 7 Update 7. That seems to be how this thing exploits people running v6 and older browsers and older OS

Fermi2

  • Guest
Re: So What Is This?
« Reply #17 on: Sep 09, 2012, 10:21 »
Yep still having to turn avast off so I can get here.

drayer54

  • Guest
Re: So What Is This?
« Reply #18 on: Sep 10, 2012, 02:20 »
Blocked request: location contains malicious content
Threat: Mal/ObfJS-CZ

Threat source : http://www.nukeworker.com/
The requested location contained malicious content and was blocked from downloading

Offline HydroDave63

  • Retired
  • *
  • Posts: 6293
  • Karma: 6629
Re: So What Is This?
« Reply #19 on: Sep 10, 2012, 02:44 »
Blocked request: location contains malicious content
Threat: Mal/ObfJS-CZ

Threat source : http://www.nukeworker.com/
The requested location contained malicious content and was blocked from downloading

what site listed that?

OLzenizin

  • Guest
Re: So What Is This?
« Reply #20 on: Sep 12, 2012, 08:45 »
it comes and goes so I just try periodically until it lets me in. I have no problem entering PolySci just the main board.

Offline Marlin

  • Forum Staff
  • *
  • Posts: 18133
  • Karma: 5147
  • Gender: Male
  • Stop Global Whining!!!
Re: So What Is This?
« Reply #21 on: Sep 12, 2012, 09:05 »
After a week of no problem it's back.

Offline GLW

  • Gold Member
  • *
  • Posts: 5499
  • Karma: 2524
  • caveo proditor,...
Re: So What Is This?
« Reply #22 on: Sep 12, 2012, 12:32 »
symantec does not seem to be having any trouble coping with this one,...

that or I'm completely hosed but don't know it yet,... :P ;) :) 8)

been there, dun that,... the doormat to hell does not read "welcome", the doormat to hell reads "it's just business"

Offline Rennhack

  • Forum Administrator
  • *
  • Posts: 9041
  • Karma: 4685
  • Gender: Male
Re: So What Is This?
« Reply #23 on: Sep 17, 2012, 11:37 »
how about now, deleted some more stuff...

drayer54

  • Guest
Re: So What Is This?
« Reply #24 on: Sep 18, 2012, 07:18 »
how about now, deleted some more stuff...

I'll check today.

 


NukeWorker ™ is a registered trademark of NukeWorker.com ™, LLC © 1996-2024 All rights reserved.
All material on this Web Site, including text, photographs, graphics, code and/or software, are protected by international copyright/trademark laws and treaties. Unauthorized use is not permitted. You may not modify, copy, reproduce, republish, upload, post, transmit or distribute, in any manner, the material on this web site or any portion of it. Doing so will result in severe civil and criminal penalties, and will be prosecuted to the maximum extent possible under the law.
Privacy Statement | Terms of Use | Code of Conduct | Spam Policy | Advertising Info | Contact Us | Forum Rules | Password Problem?