Jump to content

object HEUR:Trojan.Script.Balada.gen ?


Go to solution Solved by Berny,

Recommended Posts

Posted

Good evening, I have detected the same message on the following page from a client who coincidentally received the same alert today. Can you help me validate if the page is infected or is a false positive? 
https : //revistamujeractual.com/  → ! This infected link is disabled !

WhatsApp Image 2024-01-31 at 22.02.32.jpeg

web.PNG

Posted

@durbqw Welcome.

I reported your URL to Kaspersky Virus Lab , please wait for the verdict.

  • Like 3
Posted

@durbqw

It looks like your issue is still under investigation.
I will come back to you when the verdict is available.

  • Like 1
  • Solution
Posted

@durbqw

In the meantime  please see below the verdict that i just obtained from Kaspersky Virus Lab.
 

Quote

"Hello,

This is not a false alarm. This site is infected.
Here is the malicious code:
<...>{if (e.detail.popupId == "3823") {var uexbsh/ <...>
If you are a webmaster, please remove the above code from the page. Also we strongly recommend that you change passwords to all services that can be used to modify website contents because they may have been stolen.

Best regards, Xxxxxxxx Xxxxxxxx , Malware Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700"

 

EDIT

↓ Please see malicious script ↓

Spoiler

revistamujeractual.thumb.jpg.bcfe26fab9e5f53d581984a34f4bba59.jpg

 

  • Like 2

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...