Dodgy?

Author
Discussion

anonymous-user

Original Poster:

54 months

Tuesday 9th February 2016
quotequote all
I received am email from Linkedin yesterday and clicked....

Then realised the actual email came from eftdrcbz@mail2java.com and the link took me to this site bancoindia.in/wp-content/zoologically.php

Before I looked at the content I shut down my browser. Should I be worried I've got something nasty on my Mac now?

Tonsko

6,299 posts

215 months

Tuesday 9th February 2016
quotequote all
I just tried to download bancoindia.in/wp-content/zoologically.php and I got a 404. Did you type the URL correctly?

anonymous-user

Original Poster:

54 months

Tuesday 9th February 2016
quotequote all
Tonsko said:
I just tried to download bancoindia.in/wp-content/zoologically.php and I got a 404. Did you type the URL correctly?
Yes. I actually copied your URL to the address field in Chrome and tried it!!! Goes to a Canadian pharmacy for Viagra so assume I'm not infested!!!

It actually redirects to http://genericherbpurchase.ru/ which is Russian hosted.

Tonsko

6,299 posts

215 months

Tuesday 9th February 2016
quotequote all
But with a .ru TLD? Probably best not to click around on that site.

anonymous-user

Original Poster:

54 months

Tuesday 9th February 2016
quotequote all
Tonsko said:
But with a .ru TLD? Probably best not to click around on that site.
Agreed. I was more concerned I could 'catch' something just by being there originally. Looks like the problems would come, if any, from clicking inside the site which I have no intention of doing.

marshalla

15,902 posts

201 months

Tuesday 9th February 2016
quotequote all
It looks liked a hacked wordpress site, where the 404 page has been tweaked with a bit of javascript at the bottom to redirect to the advertising site. Moderately clever way of doing it as none of the real users are likely to notice it since most people just test their own pages and not the error conditions.

The front page of the .ru site doesn't look like it contains any malware payloads.

Tonsko

6,299 posts

215 months

Tuesday 9th February 2016
quotequote all
^^ Yeh, I pushed it through a proxy, and there was a snippet of obfuscated javascript which does the redirection to the .ru site. There was an array of numbers, which the function then took 55 from before using the javascript to string converter and then parsing the string (which was the .ru hyperlink).


marshalla

15,902 posts

201 months

Tuesday 9th February 2016
quotequote all
Tonsko said:
^^ Yeh, I pushed it through a proxy, and there was a snippet of obfuscated javascript which does the redirection to the .ru site. There was an array of numbers, which the function then took 55 from before using the javascript to string converter and then parsing the string (which was the .ru hyperlink).
Interesting - it's using php to generate variations of the obfuscated function. Grabbing it manually, the variable names change and the character offset also varies. Must be trying to avoid obvious detection methods.


Tonsko

6,299 posts

215 months

Tuesday 9th February 2016
quotequote all
That is interesting. To you and I, clearly. Not sure to anyone else... :P

anonymous-user

Original Poster:

54 months

Tuesday 9th February 2016
quotequote all
I really wish I knew what you guys were on about - but I'm just happy to be safe smile

Thanks for the replies!

Tonsko

6,299 posts

215 months

Tuesday 9th February 2016
quotequote all
You got lucky this time smile

anonymous-user

Original Poster:

54 months

Wednesday 10th February 2016
quotequote all
Tonsko said:
You got lucky this time smile
Thank god I'm not a Viagra user wink