3 ms·
Website blocked due to trojan Website blocked: nuxx.net Malwarebytes Browser Guard blocked this website because it may contain malware activity. We strongly re
by Krisjohn 4y ago
Website blocked due to trojan
Website blocked: nuxx.net
Malwarebytes Browser Guard blocked this website because it may contain malware activity.
We strongly recommend you do not continue.
Nothing is ever easy.
- pseudo0 4y agoIt's 100% clean on VirusTotal. I'm not sure what Malwarebytes has been doing lately, but I had to remove it from a relative's computer after it kept throwing false positives. https://www.virustotal.com/gui/url/54e060dd220272974a9a5bffa4aac87592721ef91f7c50facc23d2a492f03a4a/summary https://www.virustotal.com/gui/url/54e060dd220272974a9a5bffa...
- c0nsumer 4y agoI think they are using some old list, or keep around positives even after they get removed from elsewhere. I'm the OP and nuxx.net was getting flagged by Yandex because I had an old perl script, I believe udpscanner.pl, in a directory as I referenced it in some old writeup. It was actually named udpscannerl.pl.txt, was served up as text/plain, on a server with no perl CGI, and was something that needed to be run interactively from an interpreter. Literally, sample code. Yet for some reason Yandex flagged it as a malicious site. And Malwarebytes picked that up... And apparently continues to do so years after I removed the file and got Yandex to rescan and mark the site as clean.
- c0nsumer 4y agoI've been fighting with this for years, and I'm pretty sure Yandex is the problem. Hell, I even signed up for Yandex's webmaster tools as part of trying to fix this. Years ago Yandex was flagging on some sample perl code that had a .txt extension (some something like udpscanner.pl.txt or so, IIRC) that I had sitting in a directory. There's no perl CGI, no way for it to execute on the server; just sample code. IIRC it was even served up as text/plain for easy reading in browsers. It was something that would be run directly on an OS, to do some fast scanning of open ports. For an end user to run it they would have to download it and get it executed by their perl interpreter. Definitely NOT an exploit in a browser. As I recall it was something super basic that I found on a compromised server years ago and referenced in an old writeup. For some reason it was flagged by Yandex as a browser exploit, they reported up to other places, and Malwarebytes flagged the whole site as malicious. Since fighting the technical reasons why their scan is flawed is Sisyphus, I ended up just removing it from the site and getting Yandex to rescan. They now list the site as clean, but some old tools still say something untoward is going on. It's frustrating.