(The quickest way to register)

Forum

Dear visitor! The webpage is only available in English. We're sorry for the inconvenience.
  1. User picture
    • stonefist on Sun 08 Nov 2009
    • 12:15:04 PM UTC

    norrtulls.se

    This site apparently was found on a Malwaredomains blacklist. Hmm, I checked the site and...nothing bad at all. it´s an autoshop in sweden.

    http://www.mywot.com/en/scorecard/norrtulls.se

    ~You have not lived, until you´ve found something worth dying for.

Comments:

  1. User picture
    • phantazm on Sun 08 Nov 2009
    • 12:34:53 PM UTC

    Hm...

    It could be a decent site, that was temporarily infected..?

  2. User picture
    • stonefist on Sun 08 Nov 2009
    • 12:47:22 PM UTC

    ....

    It might be an ugly looking site =) but no infection occured when I visited the site.

  3. User picture
    • MysteryFCM on Sun 08 Nov 2009
    • 01:01:43 PM UTC

    .....

    The infection isn't always on the root. In this case, it's a file called redir.php, which redirects elsewhere to show a FAKE 404.

    vURL analysis
    http://vurl.mysteryfcm.co.uk/?url=1083663

    This URL is part of the Zeus botnet.

    Regards
    Steven Burn
    Ur I.T. Mate Group / hpHosts
    it-mate.co.uk / hosts-file.net

  4. User picture
    • stonefist on Sun 08 Nov 2009
    • 01:52:55 PM UTC

    ....

    Ok! but when I visit hxxp://nortulls.se It´s not redirecting me with this file- redir.php and it doesn´t show me a FAKE 404. All it shows in the URL is hxxp://nortulls.se/ not hxxp://nortulls.se/redir.php.

    Sorry for beeing so blunt about it, maybe it´s because I dont understand how these things work like you guys do.

    • User picture
      • MysteryFCM on Sun 08 Nov 2009
      • 01:59:07 PM UTC

      .....

      As mentioned, it's not always the root of the site that is involved. In some cases, it's only specific *files* on the server that are part of an infection, phishing scam or whatnot.

      Regards
      Steven Burn
      Ur I.T. Mate Group / hpHosts
      it-mate.co.uk / hosts-file.net

  5. User picture
    • stonefist on Sun 08 Nov 2009
    • 02:02:40 PM UTC

    ....

    Ok. so if/when I visit the site, I will get infected??

    • User picture
      • MysteryFCM on Sun 08 Nov 2009
      • 02:29:30 PM UTC

      .....

      If loading the site directly, then no.

      Regards
      Steven Burn
      Ur I.T. Mate Group / hpHosts
      it-mate.co.uk / hosts-file.net

  6. User picture
    • stonefist on Sun 08 Nov 2009
    • 02:37:13 PM UTC

    ....

    Ok thanks for your info on it.

  7. User picture
    • g7w on Sun 08 Nov 2009
    • 09:07:07 PM UTC

    perhaps

    Zeus Botnet
    notice the redir.php referencing:
    xxxdessert.name

    along with the malwareurl.com listing
    -------
    WOT Services Ltd. - gives us safety through Web of Trust.
    WOT Community - gives us security through unity.
    Thank you all
    - G7W

    • User picture
      • MysteryFCM on Sun 08 Nov 2009
      • 09:25:44 PM UTC

      .....

      I thought people would've noticed that or I'd have mentioned it :o(

      Regards
      Steven Burn
      Ur I.T. Mate Group / hpHosts
      it-mate.co.uk / hosts-file.net

  8. User picture
    • stonefist on Sun 08 Nov 2009
    • 09:16:07 PM UTC

    Rated and commented. Thanx

    Rated and commented.

    Thanx for the info g7w