Dubious web page

  • Please bear with us on the new site integration and fixing any known bugs over the coming days. If you can not log in please try resetting your password and check your spam box. If you have tried these steps and are still struggling email [email protected] with your username/registered email address
  • Log in now to remove adverts - no adverts at all to registered members!

Dr_Delirium

New Member
Jan 24, 2011
2
0
1
NULL
Hi everyone.

First post from me even though I signed up over a year ago and followed the old 606 forums mostly as a phantom, but had one or two posts on the old 606 before it closed.

Anyway the reason for my post is that I've been informed from my computer services that my computer was infected with a Trojan from a link about Norwich City football club. Because I'm a scientist I use Linux which usually means no problem but this one could exploit even Linux systems!? It was probably from an external website posted on here, and I'll post the response from my computer services below.

I was completely unaware and so thought it prudent to tell everyone here not only to be careful with links but to check their computer for possible malware.


Looking more closely we can see the requests were made by a Linux
system as the result of a malicious link from a website about Norwich
City football team:

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.6) Gecko/20120717
Firefox/10.0.6

The requested/redirected site has a poor reputation and is likely to
be hosting malware in particular the Blackhole exploit kit:

http://www.malwaredomainlist.com/mdl.php?search=141.8.224.25
http://www.mywot.com/en/scorecard/141.8.224.25

It is likely that what we observed was only the redirection to the
exploit site and not post-exploit behaviour - but Blackhole
specifically serves exploits based on OS and is known to include Linux.
 
I'm not entirely sure. I've used this forum for a long time and had no problems so assume it must have been from an external link posted on one of the threads. Again I'm usually cautious and the given information from the email I received, leads me to believe that something happened when I visited the site. Perhaps some code tried to re-direct my browser to a mirror site with the Trojan. If my memory serves me well I can't remember clicking on anything on the external site.

Again I was as puzzled as you are, but just thought it best to raise awareness on here in case anyone else got unlucky. I'll look through some of the old threads as I remember visiting an external NCFC blog recently which is the only link I can think of it possibly being.