LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-31-2023, 02:55 PM   #1
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Rep: Reputation: 176Reputation: 176
Virustotal scan said url was clean. But when I clicked on the url, I was redirected. A subsequent Virustotal scan showed potential trouble.


A "friend" in Facebook sent me this link. h ttps://tiktok.fb3lite.com/rQaDYRw
(I put a space between the "h"and "ttps" so no one would click on it accidentally. LQ kept illuminating it as a link)

I ran the link through Virustotal and it came out clean. https://www.virustotal.com/gui/url/c...cd3f/detection

So I clicked on it but it took me to youtube.com

Suspicious of tiktok.fb3lite.com I ran it through Virustotal and it showed https://www.virustotal.com/gui/url/4...9059/detection

I'm not very knowledgeable but I didn't like the looks of "base64-embedded" and "multiple-redirects." And when you click on "Details" it looks even scarier.


I am a bit worried. Do I need to be? Thank you.


PS. I am on a Linux computer (Xubuntu distro)
 
Old 02-01-2023, 09:32 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,789

Rep: Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304
this is written at the top of the page:
Quote:
No security vendors flagged this URL as malicious
So I don't think you need to worry about it.
 
1 members found this post helpful.
Old 02-01-2023, 09:56 AM   #3
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,596

Rep: Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545
Quote:
Originally Posted by pan64 View Post
this is written at the top of the page:

Quote:
No security vendors flagged this URL as malicious
So I don't think you need to worry about it.
???

Whether it's currently malicious or not, it's clearly a dishonest link, so shouldn't be followed/trusted on that grounds alone.

(It redirects to Youtube - why would they not simply provide the shorter and direct YouTube URL...?)

 
1 members found this post helpful.
Old 02-01-2023, 09:56 AM   #4
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,596

Rep: Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545
Quote:
Originally Posted by Gregg Bell View Post
A "friend" in Facebook sent me this link.
What did they say the link was pointing to?

 
Old 02-01-2023, 01:54 PM   #5
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by pan64 View Post
this is written at the top of the page:

So I don't think you need to worry about it.
I kind of feel the same way. But I'm still uncomfortable about it. Especially now I found out for sure my friend's Facebook account was hacked.

Last edited by Gregg Bell; 02-01-2023 at 01:56 PM. Reason: added a sentence
 
Old 02-01-2023, 01:57 PM   #6
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by boughtonp View Post
???

Whether it's currently malicious or not, it's clearly a dishonest link, so shouldn't be followed/trusted on that grounds alone.

(It redirects to Youtube - why would they not simply provide the shorter and direct YouTube URL...?)

I agree with you. And now I found out my friend's Facebook account was hacked. But I entered the entire link into VirusTotal and it came back okay.
 
Old 02-02-2023, 12:16 AM   #7
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,789

Rep: Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304
Obviously there are ways to hack your accounts, but this link is safe. You better be careful anyway.
 
Old 02-02-2023, 08:34 AM   #8
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,596

Rep: Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545Reputation: 2545
Quote:
Originally Posted by pan64 View Post
Obviously there are ways to hack your accounts, but this link is safe. You better be careful anyway.
FFS! No, the link is NOT safe. It has not yet been detected to be malicious, but not only has the domain clearly been setup to deceive, but the URL came from a compromised account.

It may be that whoever setup the redirect made a mistake and whatever malicious action should have occurred is not occurring.
It may be that they are simply testing the waters - seeing how many people follow such a link - or even attempting to determine real people from security scanners, so they can serve different content to each. (Or maybe they've already succeeded in that, and the security scans are false negatives.)
It may be that the malicious payload has a specific set of targets, and only fires for a particular range of IPs or user agents which have a known vulnerability, whilst simply performing a single redirect for everyone else.

Whatever the case, asserting that such a link is safe is irresponsible.

 
2 members found this post helpful.
Old 02-02-2023, 10:01 AM   #9
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,789

Rep: Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304
Quote:
Originally Posted by boughtonp View Post
FFS! No, the link is NOT safe. It has not yet been detected to be malicious, but not only has the domain clearly been setup to deceive, but the URL came from a compromised account.

It may be that whoever setup the redirect made a mistake and whatever malicious action should have occurred is not occurring.
It may be that they are simply testing the waters - seeing how many people follow such a link - or even attempting to determine real people from security scanners, so they can serve different content to each. (Or maybe they've already succeeded in that, and the security scans are false negatives.)
It may be that the malicious payload has a specific set of targets, and only fires for a particular range of IPs or user agents which have a known vulnerability, whilst simply performing a single redirect for everyone else.

Whatever the case, asserting that such a link is safe is irresponsible.

that assumption makes the whole internet twisty. But probably you are right.
 
Old 02-03-2023, 02:52 PM   #10
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Thanks guys. Considering that my friend's account was hacked I could not consider having clicked on the link safe. I clean installed a new version of Xubuntu.
 
Old 02-13-2023, 11:03 PM   #11
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,219

Rep: Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309Reputation: 5309
I tried to google the link's domain, and my first few hits were for the other places you posted this: :P

https://www.techguy.org/threads/init...blems.1286083/

https://www.reddit.com/r/antivirus/c...an_but_when_i/

FWIW, I can't curl the URL, and whois says the domain was registered through namecheap.com.

Last edited by dugan; 02-13-2023 at 11:14 PM.
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] umount said /dev/sdd is not mounted; yet lsblk said it is mounted to /run/media/ ? andrewysk Linux - Newbie 8 05-29-2021 04:29 PM
Why Does the Leading / Get Removed From the URL When the Link is Clicked On in Google? ehswift71 Debian 1 01-09-2019 06:05 PM
Potential Exploit? Potential Backdoor? Strange code in '/usr/android/adb' Package: android-tools-adb slicktrail Linux - Security 1 12-05-2016 05:05 AM
I said, "howdy;" she said, "hi." NoTinyFlacid LinuxQuestions.org Member Intro 1 11-21-2010 08:27 PM
pixel view card showed 1024x768 but nv riva tnt2 can't abs Linux - Hardware 4 02-29-2004 05:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration