Jump to content

ArtToFrames reported file through users


aaroncalvo
Go to solution Solved by Dashke,

Recommended Posts

I tested the file on virus total and malwarebytes was the only result that came back as an issue. 

The file was not updated in weeks and did not see this result prior

 

https://www.virustotal.com/#/url-analysis/u-1bdf9586dd242be8f8a8a9d7c97c8738172fae7d5b215f91cb56a8343301613a-1549489523

 

home page showing clean =  https://www.virustotal.com/#/url/1bdf9586dd242be8f8a8a9d7c97c8738172fae7d5b215f91cb56a8343301613a/detection

the file in question loaded through header of page (so home page as well as others ) showing with issue = https://www.virustotal.com/#/url/f70c97d7147ecca94f32a63abd838fb1c4bd1fdacce39aa9aed65a67e5c389b2/detection

 

I have attached the screenshot from a customer as well as the file that was mentioned by customer and the file from his screenshot.

 

This  was the customers comments:

Quote

Comment - Please get me in touch with your IT team. It looks like you have a 
piece of malicious Javascript running in your site. Looks to be a Trojan horse known as JS/Spy.Banker.DF

malicious URLS

hxxps://cdn6.arttoframe.com/notification/messaging/generateToken.js 

 

df26e0f95155164544d98af6af5eb9c2.thumb.png.b45c7cb95d1a29da9228434e7a8728a0.png

header_js_block.zip

Edited by Dashke
Link to post
Share on other sites

  • Dashke locked this topic
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.