Jump to content

Here's the low down on Jamie Oliver's website virus issue


Recommended Posts

Posted
Daughter uses this site a lot and had no apparent problems. I saw this earlier today and am currently guiding her through throwing the anti malware toolset at her laptop. Fortunately Java was up to date with no old versions, but we are doing a clean install to be on the safe side.
Posted
Our SCCM Forefront has been picking up on this for for at least 6 weeks - as a post above I thought it was a false positive so just ignored it. I'm surprised it's taken that long for them to pick it up.
Posted
And people knock it. We also run sophos and that didnt pick it up...

 

Its free (kinda), darn simple (well once you have a SCCM server running) and 'just works' keeps me happy!

  • Thanks 1
Posted (edited)
shouldn't Smoothwall pickup on these kinds of things

You would have thought so, but VIPRE anti-virus is pretty rubbish in terms of protection according to AV-Test (worse than AVG!).

 

I suppose you could block all .xyz domains, octet-streams for staff and students and install/configure EMET.

 

Edit. According to the blog post above...

 

The Exploit Kit launched at least three exploits (Flash (CVE-2015-0311), Silverlight (CVE-2013-0074) and Java) which were successfully blocked by Malwarebytes Anti-Exploit.

 

The exploit was stopped at Layer 1 (ROP gadget) as it was calling the VirtualAlloc API.

 

http://a.pomf.se/oiywjd.png

 

I think EMET would definitely help in this case (assuming your plugins weren't up-to-date).

Edited by Arthur
Posted (edited)
Does anyone have a screenshot of their first detection of the problem? (either email or av console)

 

I don't have the first one as we just delete our notifications after a month, here is the oldest notification we have:

 

Configuration Manager Endpoint Protection has detected malware on one or more computers in your organization

 

Collection name: -

 

Malware Name: Exploit:JS/Fiexp.C

Number of infections: 1

Last detection time(UTC time): 1/22/2015 10:31:33 AM

 

These are the infections of this malware:

1. Computer name: -

Domain: -

Detection time(UTC time): 1/22/2015 10:31:33 AM Malware file path: webscript:_http://www.jamieoliver.com/news-and-features/features/flavoured-breads/#tkwjEuwgVG0fxkZh.97

Remediation action: Remove

Action status: Succeeded

To view further information about malware activity in your organization, run Malware Details Report.

 

Note: No additional Malware Detection alerts will be generated for these computers if no new infections are found in the next 24 hours.

 

Edit: Turns out this is the earliest one, I thought I had seen one before this but doesn't look like it.

Edited by JRowley
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...