Advice Request HEUR:Trojan-PSW.Script.Generic

Please provide comments and solutions that are helpful to the author of this topic.
Sent to ESET with the response of Kaspersky and ESET is gonna add it to their signatures in the next update
View attachment 230031
Hello,
Just checked with ESET on a friend laptop. NOD32 detects the threat(y)
What's up with the other antivirus ?
MiotESET.PNG
 
Hello,
Just checked with ESET on a friend laptop. NOD32 detects the threat(y)
What's up with the other antivirus ?
View attachment 230114
I have sent the complete script to almost all AV vendors. Let's see how many of them add it to their signatures.
VirusTotal link: VirusTotal
 
I have sent the complete script to almost all AV vendors. Let's see how many of them add it to their signatures.
VirusTotal link: VirusTotal
Thanks @SeriousHoax
I'm wondering about how VirusTotal works because Kaspersky was the first AV to detect this threat and it doesn't yet appear on the list of AV that detect this URL:unsure:
Also I don't understand the difference between this two VT check : VirusTotal and VirusTotal
 
I'm wondering about how VirusTotal works because Kaspersky was the first AV to detect this threat and it doesn't yet appear on the list of AV that detect this URL
VT usually does not reflect properly Kaspersky detections, in these cases You can check if ZoneAlarm does, because it uses Kaspersky engine ;)
 
Also I don't understand the difference between this two VT check : VirusTotal and VirusTotal
Like harlan4096 said, VT often doesn't reflect the actual detection and this is more common for URLs than actual sample. Also some AV may not block the site but detect the malicious script it loads.
 
Update: It seems the website has been fixed. It doesn't load that malicious script anymore so safe to visit and purchase again. Cheers :emoji_beer:
Hello @SeriousHoax
You answered my question before I ask it:unsure:
I just noticed that Kaspersky no longer blocks thi site.
But Netcraft always blocks it.
 
Hello @SeriousHoax
You answered my question before I ask it:unsure:
I just noticed that Kaspersky no longer blocks thi site.
But Netcraft always blocks it.
Kaspersky never blacklisted the site but it by default scans encrypted connections in browsers so it knows whether any known malicious script has loaded or not while Netcraft can't do that and they simply put the site in blacklist I suppose. So, that's the reason.