All-clear: Virus attack from totalcmd.net !
Moderators: Hacker, petermad, Stefan2, white
All-clear: Virus attack from totalcmd.net !
When I start totalcmd.net in Firefox 3.6.20 I get a Java popup window and a firewall alarm of this trojan (scan at virustotal.com) on WinXP. Please be aware until admin of totalcmd.net gives the all-clear.
Last edited by tbeu on 2011-11-07, 09:42 UTC, edited 2 times in total.
My Firefox 7.0.1 with "AVG Free Edition" tells me
Short translation:
"active harrassment; blocked; known Exploit-, Phishing- or Social Engineering-Website"
Peter
Code: Select all
Gefahr: Surf-Shield hat auf dieser Seite aktive Bedrohungen erkannt und zu Ihrem Schutz den Zugriff blockiert.
Die Seite, auf die Sie zugreifen möchten, wurde als bekannte Exploit-, Phishing- oder Social Engineering-Website identifiziert und daher zu Ihrer Sicherheit blockiert. Ohne Schutz, wie beispielsweise durch AVG Security Toolbar und AVG, besteht die Gefahr, dass Ihr Computer beschädigt oder Ihre persönlichen Daten gestohlen werden. Wählen Sie eine der unten angeführten Optionen aus, um fortzufahren.
URL: cick.chickenkiller.com/sys/main.php?page=fb14c1b3b6e4c496
Name: Blackhole Exploit Kit (type 1889)
"active harrassment; blocked; known Exploit-, Phishing- or Social Engineering-Website"
Peter
TC 10.xx / #266191
Win 10 x64
Win 10 x64
-
- Member
- Posts: 142
- Joined: 2003-02-07, 12:54 UTC
Thanks for the warning, I remoed the malicious code now.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.03 / Win10 x64
Using TC 11.03 / Win10 x64
For your information:
http://www.webopedia.com/TERM/B/blackhole_exploit_kit.html
BlackHole Exploit Kit
A type of crimeware Web application developed in Russia to help hackers take advantage of unpatched exploits in order to hack computers via malicious scripts planted on compromised websites. Unsuspecting users visiting these compromised sites would be redirected to a browser vulnerability-exploiting malware portal website in order to distribute banking Trojans or similar malware through the visiting computer.
Blackhole exploit kits are based on PHP and a MySQL backend and incorporate support for exploiting the most widely used and vulnerable security flaws in order to provide hackers with the highest probability of successful exploitation. The kits typically target versions of the Windows operating system and applications installed on Windows platforms.
The first Blackhole exploit kit appeared on the black market in August 2010 as a Web application available for sale on a subscription basis ($1,500 for an annual license). Newer releases and a free version of the Blackhole exploit kit have since appeared on warez download sites. The most well-known Blackhole exploit kit attack targeted the U.S. Postal Service's Rapid Information Bulletin Board System (RIBBS) website in April 2011.
Thanks. There are still two open questions. How did it get infected? And how likely is a re-infection?Flint wrote:Thanks for the warning, I remoed the malicious code now.
TC plugins: Autodesk 3ds Max / Inventor / Revit Preview, FileInDir, ImageMetaData (JPG Comment/EXIF/IPTC/XMP), MATLAB MAT-file Viewer, Mover, SetFolderDate, Solid Edge Preview, Zip2Zero and more
Unfortunately, I'm not a security expert, so I'm unable to answer these questions.tbeu wrote:How did it get infected? And how likely is a re-infection?

Since it's not the first time, I suspect there is some open hole in the server, but how to find it it beyond my abilities. I'll ask Ergo (the owner of the site) to contact the hoster company, maybe they'll be able to help.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.03 / Win10 x64
Using TC 11.03 / Win10 x64