- Archived
Getting Web Attack: Exploit Toolkit Website 115 alerts from Norton Security while using Firefox
I keep getting alerts from Norton while browsing ran Norton's scan and MBAM then ran Norton's Power Eraser. I did not fine the source of the problem. I added an entry t… (read more)
I keep getting alerts from Norton while browsing ran Norton's scan and MBAM then ran Norton's Power Eraser. I did not fine the source of the problem. I added an entry to my hosts file hoping it would block the IP but it doesn't seem to work, I may have done something wrong. The entry I made is: 103.224.212.246 0redird.com at the end of the hosts file. Below is the log from Norton security, the full URL is very long:
Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 9/8/2022 4:29:31 PM,High,An intrusion attempt by 0redird.com was blocked.,Blocked,No Action Required,Web Attack: Exploit Toolkit Website 115,No Action Required,No Action Required,"0redird.com (103.224.212.246, 80)","http://0redird.com/jr.php?gz=1OEmizLy7QYVD%2F%2B2wVJzO349fnNvVUhsTGdjbWhyaGllTWp3YzVnNkNISUJUcy90a3J0dk1WOVcvWFp1akhIZk9IV1gzSUhCUVlqelYzZGNPbEx3eUVIdGllWjlybTVQaGpMRWFLaEVZMSt4RURuLzFtQUI0WXowUU83d0VZM2JybmZ5WFZaaXVKTFJlM0tBeHg3R2Z6RTRHeXlybG1lYmFjSFBGSFZlY2FJNVBOREhZUEJDZWU3OFhyaDFiNEZwSU5Da0x6YndWaWNtc1RCVHZUWHBVMjREQ1RoVU1VRlFuUUduNmdwYW5LYWFTYjFaNVFWcnhmSGdWL1RTY3Nvc3k4TEpCaGdzeFlmeCsrS0FIb0pqazNrZFppUXRKZEg0MlFrNkUwSlRGRXJQaXNBRVFrdUhETENVMU45NDNYVmFuMzgyZHhBeTg4dS9FdlB2aXdKQ2pYL3RUVkNMeC9YSVZLcThLWkk1SkhiRnhtR2JiM3lZSTBncjJ1OTdqRkg3Nk5zS3JBR1E5M1NnU2Q0SmNpNlZkaE82ajRWd2hPd2hma0FEM1BXdC9RUmxQZnFldlF1NG5wSFRyZVBBNzBCanJKbGRDVEQ3YkU5TWUyYjUwejBHS2lvSmdtZmc5dWlWbG5xakFNR0xsU2tMS0syaUNFdHNwVFBVZmxqOHNmbCtXRldNaWx6MlpPTit5VDdpRTFNZi9nL3VHMUh0QVRuNU0yTmJYeU5DaDNKN2pQUXpLY0J2TkdxZTRwRklGRllzUzJWNUJBclhuRklKYTI1WWM2d1hScERqUGdPazhxR1MrR210cm13VUdpLzlySTRIK2kwempGUXR6UDZyMU1sWUd1S1FxTFBoZkMvTExKVWszSWxldzVHSHRJR3ZYMGlZWThOTXZ5TjFPOXBqWlROK1RpKzNNd09FWHZjc0hYQzJxSm9TQlR3ZjdFQ1lKd3gvY1JTTTh1VTYzOXg3MUxuNGRvOUhXQXBiN3ZhTndHMzc1dVVLUFIxQVpEck94UVRyRjVhWFpGMzhmM0pLOWsxRDVKdEVIdU1MV2crWnZoODFYL21wZ3FZWDRQZ2ZFcXhZRTNaZUQrWmdGMGNsQTRtZ1drdm1ENkVWV29EOWl3NUJHcVJxbTBRd1o1aGVYbHZJMmZhaG1BWEpBQ2NIOTBrbktVcWxySmdONDFXZTlrdVNDVThNczFvQnkxdzllakFZS0pveUswNzJkd0ovMHhpL0Y5OUpFYmsyTXVHdkxqSXJDNFlJQmk3MERCOTBXZ1Q2VjUzU0hpOXZ4d21QSjlkUGdRamxPZlJmUHJOOEdtbEVOdjhuWitVbjYwbkkxQmxEMTRRcHg5T1Z6MWprRXc0MEx5VGMweEZLdFUyZ21LNGlXVm15d21jS3lkU25vZFFNejJTMWRaZ1F0Uk9WMlEyMFdNWHlPRUJoNXUvM2REUUNsU0NQY2ROcUNzaUlFMDBCZExab24rTTNpWjZTRk5SaUlZVSt6TkJ3S3JZTkdjbmJBWVVsODFic0g0V0FHKzBWLzRrOVNnUXdEemtLaTJrQzBPYlBWY29ZZ285VFVXeEwrK0Y0MDFhUUwyY295YUJCVDlBM3lTcW5pcGpPYVB3WXVIRXRPc0gxRUNrWGl2d1NXZDlsVVExUXdYdmdTZFk0SXlka2hoUVVJZGFjZ05vVzRYSkw1SzBXV0NaNHRQK3lmRFdXUzNDaGpuTWZMV0ZzVnFEaWxmTTBMMTBEOUNBRkt5cFFUZW9QeTlJWnhTODQveEZnZHREY0d1QWhNdWdkcDFwcU1BTkRQdVIwTTcvclA5UzRtaXRlb0JkTXBLMHJqYy94RzhXaDk5SEdHT01WWWl1b2ZlV3Z6NDlVTWloRnVQNnpsNUc2c2RQYTl5bHkzKzNhK1laeE9wbXRDTTJ2V3VNZ2lsWWdTWkJ5UlVoWnRlM0tzVjNuNmMwSXVMUFJreFFNdmN3byswNHgrSVlIbzVENGdaNHM1cWJNUy9LbU9MSWNwUklaQT09&vs=1024:576&ds=1920:1080&sl=0:0&os=f&nos=f&swfV=0.0.0&if=f&sc=f&gpu=Google%20Inc.%20(Intel)%20-%20ANGLE%20(Intel,%20Intel(R)%20HD%20Graphics%20Direct3D11%20vs_5_0%20ps_5_0)&anura_res=","FANMAN-PC (192.168.0.101, 2237)",0redird.com (103.224.212.246),"TCP, www-http" Network traffic from http://0redird.com/jr.php?gz=1OEmizLy7QYVD%2F%2B2wVJzO349fnNvVUhsTGdjbWhyaGllTWp3YzVnNkNISUJUcy90a3J0dk1WOVcvWFp1akhIZk9IV1gzSUhCUVlqelYzZGNPbEx3eUVIdGllWjlybTVQaGpMRWFLaEVZMSt4RURuLzFtQUI0WXowUU83d0VZM2JybmZ5WFZaaXVKTFJlM0tBeHg3R2Z6RTRHeXlybG1lYmFjSFBGSFZlY2FJNVBOREhZUEJDZWU3OFhyaDFiNEZwSU5Da0x6YndWaWNtc1RCVHZUWHBVMjREQ1RoVU1VRlFuUUduNmdwYW5LYWFTYjFaNVFWcnhmSGdWL1RTY3Nvc3k4TEpCaGdzeFlmeCsrS0FIb0pqazNrZFppUXRKZEg0MlFrNkUwSlRGRXJQaXNBRVFrdUhETENVMU45NDNYVmFuMzgyZHhBeTg4dS9FdlB2aXdKQ2pYL3RUVkNMeC9YSVZLcThLWkk1SkhiRnhtR2JiM3lZSTBncjJ1OTdqRkg3Nk5zS3JBR1E5M1NnU2Q0SmNpNlZkaE82ajRWd2hPd2hma0FEM1BXdC9RUmxQZnFldlF1NG5wSFRyZVBBNzBCanJKbGRDVEQ3YkU5TWUyYjUwejBHS2lvSmdtZmc5dWlWbG5xakFNR0xsU2tMS0syaUNFdHNwVFBVZmxqOHNmbCtXRldNaWx6MlpPTit5VDdpRTFNZi9nL3VHMUh0QVRuNU0yTmJYeU5DaDNKN2pQUXpLY0J2TkdxZTRwRklGRllzUzJWNUJBclhuRklKYTI1WWM2d1hScERqUGdPazhxR1MrR210cm13VUdpLzlySTRIK2kwempGUXR6UDZyMU1sWUd1S1FxTFBoZkMvTExKVWszSWxldzVHSHRJR3ZYMGlZWThOTXZ5TjFPOXBqWlROK1RpKzNNd09FWHZjc0hYQzJxSm9TQlR3ZjdFQ1lKd3gvY1JTTTh1VTYzOXg3MUxuNGRvOUhXQXBiN3ZhTndHMzc1dVVLUFIxQVpEck94UVRyRjVhWFpGMzhmM0pLOWsxRDVKdEVIdU1MV2crWnZoODFYL21wZ3FZWDRQZ2ZFcXhZRTNaZUQrWmdGMGNsQTRtZ1drdm1ENkVWV29EOWl3NUJHcVJxbTBRd1o1aGVYbHZJMmZhaG1BWEpBQ2NIOTBrbktVcWxySmdONDFXZTlrdVNDVThNczFvQnkxdzllakFZS0pveUswNzJkd0ovMHhpL0Y5OUpFYmsyTXVHdkxqSXJDNFlJQmk3MERCOTBXZ1Q2VjUzU0hpOXZ4d21QSjlkUGdRamxPZlJmUHJOOEdtbEVOdjhuWitVbjYwbkkxQmxEMTRRcHg5T1Z6MWprRXc0MEx5VGMweEZLdFUyZ21LNGlXVm15d21jS3lkU25vZFFNejJTMWRaZ1F0Uk9WMlEyMFdNWHlPRUJoNXUvM2REUUNsU0NQY2ROcUNzaUlFMDBCZExab24rTTNpWjZTRk5SaUlZVSt6TkJ3S3JZTkdjbmJBWVVsODFic0g0V0FHKzBWLzRrOVNnUXdEemtLaTJrQzBPYlBWY29ZZ285VFVXeEwrK0Y0MDFhUUwyY295YUJCVDlBM3lTcW5pcGpPYVB3WXVIRXRPc0gxRUNrWGl2d1NXZDlsVVExUXdYdmdTZFk0SXlka2hoUVVJZGFjZ05vVzRYSkw1SzBXV0NaNHRQK3lmRFdXUzNDaGpuTWZMV0ZzVnFEaWxmTTBMMTBEOUNBRkt5cFFUZW9QeTlJWnhTODQveEZnZHREY0d1QWhNdWdkcDFwcU1BTkRQdVIwTTcvclA5UzRtaXRlb0JkTXBLMHJqYy94RzhXaDk5SEdHT01WWWl1b2ZlV3Z6NDlVTWloRnVQNnpsNUc2c2RQYTl5bHkzKzNhK1laeE9wbXRDTTJ2V3VNZ2lsWWdTWkJ5UlVoWnRlM0tzVjNuNmMwSXVMUFJreFFNdmN3byswNHgrSVlIbzVENGdaNHM1cWJNUy9LbU9MSWNwUklaQT09&vs=1024:576&ds=1920:1080&sl=0:0&os=f&nos=f&swfV=0.0.0&if=f&sc=f&gpu=Google%20Inc.%20(Intel)%20-%20ANGLE%20(Intel,%20Intel(R)%20HD%20Graphics%20Direct3D11%20vs_5_0%20ps_5_0)&anura_res= matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE. To stop being notified for this type of traffic, in the Actions panel, click Stop Notifying Me. Any help will be appreciated, I can't find any info about this exploit inmy web searches.