Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 19th, 2012, 05:19 AM
Snowden Snowden is offline
Regular Poster
 
Join Date: May 2012
Posts: 68
Default potential malicious redirect? I'm unsure.

Some background: I use Sandboxie, Chrome w/ https everywhere, adblock plus and ghostery

AV: Avast free

It's late, a buddy of mine posted a shortened link on twitter...being bored I clicked on it and it was a redirect to google. That seemed odd.

The URL he pasted: (don't click) hxxp://t.co/FXqVa21T

I used LongURL to expand it:


Title:Google
Short URL: hxxp://t.co/FXqVa21T
Redirects:
3 (hide details)

hxxp://goo.gl/x0zuW
hxxp://shoppingcorp.info/
hxxp://www.google.com/

Long URL: http://www.google.com/

Did a whois on the domain..

Domain Name:SHOPPINGCORP.INFO
Created On:29-Aug-2012 09:37:24 UTC
Last Updated On:25-Sep-2012 11:00:07 UTC

But, to be safe, I changed the password of all logged in accounts....any suggestions/guidance?
  #2  
Old October 19th, 2012, 05:43 AM
Snowden Snowden is offline
Regular Poster
 
Join Date: May 2012
Posts: 68
Default Re: potential malicious redirect? I'm unsure.

Sorry for posting the link. Can someone remove that please? I can't edit the post.
  #3  
Old October 19th, 2012, 06:11 AM
Get's Avatar
Get Get is offline
Frequent Poster
 
Join Date: Nov 2009
Location: the Netherlands
Posts: 374
Default Re: potential malicious redirect? I'm unsure.

Ask the buddy what the link was which he shortened? Maybe it was something on ShoppingCorp.com which is now for sale.
__________________
if I were you I wouldn't bother,
for there are brighter sides to life and I should know,
because I've seen them,
but not very often.
  #4  
Old October 19th, 2012, 06:49 AM
Snowden Snowden is offline
Regular Poster
 
Join Date: May 2012
Posts: 68
Default Re: potential malicious redirect? I'm unsure.

I sent a message but haven't heard back from him... it was also about 0400 when it was posted.
  #5  
Old October 19th, 2012, 06:55 AM
TheWindBringeth TheWindBringeth is offline
Frequent Poster
 
Join Date: Feb 2012
Posts: 846
Default Re: potential malicious redirect? I'm unsure.

I see hxxp://t.co/FXqVa21T doing a meta refresh/location.replace to hxxp://goo.gl/x0zuW which 301s to hxxp://shoppingcorp.info/ which 302s to hxxp://www.google.com/. Nothing in those exchanges worth noting. Used FF.
  #6  
Old October 19th, 2012, 06:58 AM
Snowden Snowden is offline
Regular Poster
 
Join Date: May 2012
Posts: 68
Default Re: potential malicious redirect? I'm unsure.

Thanks

but, still.. it's just weird
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:45 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums