Jump to content

Should I worry about this redirect?


Go to solution Solved by Flood and Flood's wife,

Recommended Posts

Eduardo Arakaki
Posted

I was going to watch something in a website that I've always used and never got any kind of redirect or suspicious thing going on with it, but today something happened. 
When using it, I got redirected to a ''Malicious link'' (from what Kaspersky said).

The thing is, Kaspersky only said they detected the Malicious Link and that it had ''probability of unauthorized software download''. No message about blocking such a thing as a download or whatsoever. I closed it in a second, but I know very well that this doesn't mean I am safe at all.

I'll show the link to where it did redirect me, if anyone know something about it, please tell me if I should worry about it or not. And I will be breaking the link so that nobody clicks it by mistake.

Here it is: https://superlativefireman.com/vd22xhd8w?ihzgyk=94&refer=https://anix.to/home&kw=["anix","-","watch","anime","online","free","anime","streaming"]&key=13a2cc546d58c4e8026278f34cba6491&scrWidth=1920&scrHeight=1080&tz=-3&v=24.1.v.10&ship=&psid=CF-3084_layer_1&sub3=invoke_layer&res=14.31&dev=r&adb=y&adb=y

https://superlativefireman.com/vd22xhd8w?ihzgyk=94&refer=https://anix.to

And the last one is https: //  superlativefireman.com/api/users?token=L3ZkMjJ4aGQ4dz9hZGI9eSZkZXY9ciZpaHpneWs9OTQma2V5PTEzYTJjYzU0NmQ1OGM0ZTgwMjYyNzhmMzRjYmE2NDkxJmt3PSU1QiUyMmFuaXglMjIlMkMlMjItJTIyJTJDJTIyd2F0Y2glMjIlMkMlMjJhbmltZSUyMiUyQyUyMm9ubGluZSUyMiUyQyUyMmZyZWUlMjIlMkMlMjJhbmltZSUyMiUyQyUyMnN0cmVhbWluZyUyMiU1RCZwc2lkPUNGLTMwODRfbGF5ZXJfMSZwc3Q9MTcwNTU1MDE3MCZyZWZlcj1odHRwcyUzQSUyRiUyRmFuaXgudG8lMkZob21lJnJlcz0xNC4zMSZybXRjPXQmc2NySGVpZ2h0PTEwODAmc2NyV2lkdGg9MTkyMCZzaGlwPSZzaHU9NmY1OTg0MTQzOTUwOTU2ZmU2MzgyZDE3NjUzMjBkODkxYWM1NzQyNGYwNGFmNDlmOTJjN2JhMDUzZGE1NTNjNDQ3MzhjYjM1Nzc5ZWRjYzkyNTMxZDYwMGMwM2M5YmY3NmFhODlhMjExMWE5NDA5OWZkNzM3NjMwY2I3N2YyMmI1YjViM2UzOGVlZWUxZjIzN2UzOWFmOWMzOGJhOGViNWZhODhjYjJiNzJjOTliMjRhNWQwZjkwNThmYmEmc3ViMz1pbnZva2VfbGF5ZXImdHo9LTMmdj0yNC4xLnYuMTA%3d&uuid=&pii=&in=false


Ah, just one more thing. While I wrote this, I noticed that Kaspersky told me that they blocked a download from the link just from me writing it down. Is that even possible? For a link to download something just from you writing it down? And this time they told me something about blocking a download just from me writing it down, but when I did click on the link sooner, they didn't. 

  • Solution
Flood and Flood's wife
Posted (edited)
42 minutes ago, Eduardo Arakaki said:

I was going to watch something in a website that I've always used and never got any kind of redirect or suspicious thing going on with it, but today something happened. 
When using it, I got redirected to a ''Malicious link'' (from what Kaspersky said).
The thing is, Kaspersky only said they detected the Malicious Link and that it had ''probability of unauthorized software download''. No message about blocking such a thing as a download or whatsoever. I closed it in a second, but I know very well that this doesn't mean I am safe at all.

I'll show the link to where it did redirect me, if anyone know something about it, please tell me if I should worry about it or not. And I will be breaking the link so that nobody clicks it by mistake.

Ah, just one more thing. While I wrote this, I noticed that Kaspersky told me that they blocked a download from the link just from me writing it down. Is that even possible? For a link to download something just from you writing it down? And this time they told me something about blocking a download just from me writing it down, but when I did click on the link sooner, they didn't. 

Hello @Eduardo Arakaki

Welcome!

  1. Kaspersky has blocked site & protected (your) computer.
  2. As (you've) previously used the website without issue, it's possible it's been contaminated, we've sent it to Kaspersky's Virus Lab for analysis, please wait for their response. 

2024-01-18_160746.thumb.png.b3ad3e88e2f738effb297dec7c3bdeff.png

2024-01-18_160840.thumb.png.7a16936bf5ae9d247b87736625048295.png

2024-01-18_160922.thumb.png.b6cd8015fdd2bf11a6ef8dc9cd20f0e8.png

Thank you🙏
Flood🐳+🐋

Edited by Flood and Flood's wife
spelling
  • Like 1
Eduardo Arakaki
Posted
16 horas atrás, Flood and Flood's wife disse:

Hello @Eduardo Arakaki

Welcome!

  1. Kaspersky has blocked site & protected (your) computer.
  2. As (you've) previously used the website without issue, it's possible it's been contaminated, we've sent it to Kaspersky's Virus Lab for analysis, please wait for their response. 

2024-01-18_160746.thumb.png.b3ad3e88e2f738effb297dec7c3bdeff.png

2024-01-18_160840.thumb.png.7a16936bf5ae9d247b87736625048295.png

2024-01-18_160922.thumb.png.b6cd8015fdd2bf11a6ef8dc9cd20f0e8.png

Thank you🙏
Flood🐳+🐋

Thanks!

So it seems like I'm safe, I have done two full scans on my computer and Kaspersky said there's nothing. I guess I shouldn't worry, then.

Where can I see the results of the analysis?

 

  • Thanks 1
Guilhermesene4096
Posted
 
You can view all the details of the scans performed by following the steps in the photos below.
 
01.thumb.png.87c908f4538970ffa4bb9c39db7e513f.png
 
02.thumb.png.72277e9cba61560d02812b12534c2071.png
 
Sincerely,
 
Guilherme
  • Like 3
Flood and Flood's wife
Posted (edited)
3 hours ago, Eduardo Arakaki said:
  1. Where can I see the results of the analysis?
  2. So it seems like I'm safe, I have done two full scans on my computer and Kaspersky said there's nothing. I guess I shouldn't worry, then.

Hello @Eduardo Arakaki

You're most welcome!

  1. We've sent it to Kaspersky's Virus Lab for analysis, please wait for their response. When it's available we will post it in this topic. 
  2. Correct, do not worry. You've run two scans, Kaspersky said there's nothing.
  3. When you run *any* scan - at the end - select the Report icon, it will take you *directly* to the relevant Scan report - see images

scan-merge-eduardo.thumb.png.603da71e3864a1047eba75ccf9ab084b.png

Thank you🙏
Flood🐳+🐋

Edited by Flood and Flood's wife
added images
Flood and Flood's wife
Posted
23 hours ago, Eduardo Arakaki said:

I was going to watch something in a website that I've always used

Hello @Eduardo Arakaki

Follow-up, from the Virus Lab experts, the superlativefireman alert is a valid warning, however, please check anix again, does the redirect or download alert repeat? IF 'yes', please reset each browser (you) use, for Google: chrome://settings/reset; for Edge: edge://settings/reset; for Firefox: https://support.mozilla.org/en-US/kb/refresh-firefox-reset-add-ons-and-settings#w_refresh-firefox; at the completion of the reset of whichever browser(s) (you) use, exit the browser(s), then shutdown the computer, using Shutdown, not restart, power on the computer by pressing the power button, login, recheck? 

Please share the outcome with the Community? 

Thank you🙏
Flood🐳+🐋

  • Like 1
Posted

@Eduardo Arakaki

This redirect issue  is strange , no Ping reply and a suspicious Java Script object 🤔

Spoiler

ping.thumb.jpg.cec52c3d2fe7b6e9456fa3cf8bfc792f.jpg

 

super.jpg.72507e02cfea563fa90b088b18e0e42b.jpg

 

Flood and Flood's wife
Posted

 superlativefireman is not the primary site, it's the redirect. Nothing strange about it. 

Kaspersky's Virus Lab experts have *already* said it's a valid warning.

We've *already* issued the Kaspersky Threat Intelligence Portal report. 

The case is *pending* a response from @Eduardo Arakaki & *is in hand* with Kaspersky's Virus Lab experts. 

What exactly is it that you find so strange - that is not already under investigation @Berny

Posted

@Eduardo Arakaki

↓ From Kaspersky Virus Lab ↓
 

Quote

"Hello,

The detection is correct.

Sincerely, Xxxxxxxxx Xxxxxxxxx
Malware Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700"

 

harlan4096
Posted

Also, run AdwCleaner tool if redirect still there...

  • Like 4

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...