Jump to content

Recommended Posts

Posted

When I try to open the web.telegram.org page,
HEUR:Trojan.Script.Miner.gen is attempting to infect my computer with malware.

Posted

Welcome to Kaspersky Community.

 

Please provide versions of K. product installed.

 

Also, post a capture with the details of the detection.

 

I can't reproduce the detection here 🤔 neither in my Kaspersky nor in VirusTotal service.

Posted

HI,

it happened the same to me and others, here is the reddit post form yesterday.

Any official information about this?

 

Thanks!

Posted

↓ Same redirection to 'web.telegram.org' here ↓

Spoiler

telegram_01.thumb.jpg.f9bd89db6c772972fc66652c759a4d63.jpg

 

telegram_02.jpg.2e2b570a783083487ea7425301f93066.jpg

 

 

  • Like 1
Posted

Type: Trojan
Name: HEUR:Trojan.Script.Miner.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: 3640.61daa6ed9a8f1e122076.js
Object path: https : //web.telegram.0rg/a/

Malware Links :

change the 0rg to org in address

https: // web.telegram.0rg/a/3640.61daa6ed9a8f1e122076.js
https: // web.archive.0rg/web/20250604202003if_/https://web.telegram.0rg/a/3640.61daa6ed9a8f1e122076.js

Screenshot_2.jpg

Posted

Exactly, that URL is not the same, that one has a "zero" number instead of the letter "o". So those URLs with .0rg are fake, and they are correctly flagged as malware!

  • Like 1
Posted (edited)

I know it's spam, but I wrote it that way so that others wouldn't automatically click on it 🙂
The malicious JS file was on the official website.
I wrote the malicious file as .0rg so that it wouldn't harm others.


i said before
change the 0rg to org in address

Edited by U.A

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...