FMA Intel-Secure home page attacked by ransomware??

Nico@FMA

Level 27
Thread author
Verified
May 11, 2013
1,687
sT2ZkOw.png

Is this a freaking joke? I get a call at home from OVH technical staff that some script is bashing my site?
Really? dulesky.0pu .ru
Seems some server has randsomware on it and tries to inject it in my site? For some odd reason i cannot look up server side (guess the script blocks it to avoid me finding out who or what so maybe one of you guys can do a trace and post me the details.

Be carefull..

Cheers
 
Last edited by a moderator:
  • Like
Reactions: Malware1

Nico@FMA

Level 27
Thread author
Verified
May 11, 2013
1,687
http://dulesky.0pu.ru/ hosts Pony stealer, i'll add it to CyberTracker.

Thanks.

I have already blocked host & ip & domain using server side firewall, session, cookie and .htaccess
Also i have blacklisted the domain at malicious URL reporter (security feature by OVH if a site tries to hack it will be blacklisted world wide)
So it will not take long before google will block it as well.

Pony is a credential stealer and is also used to install banking Trojans such as Zeus. Pony is typically installed onto a computer via a malicious website.
 

Nico@FMA

Level 27
Thread author
Verified
May 11, 2013
1,687
Theyre working on a web blocking feature, so maybe it has something to do with it.

Sucuri: http://sitecheck.sucuri.net/results/dulesky.0pu.ru

Take a look on Website details:)

Lol this sitecheck.securi.net even classes my website as malicious and says i got 404javascript.js on my site which rewrites the .htaccess file.
Really?o_O Lol you got to be kidding me right?
Thats the biggest joke in history.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top