Websites Blocked by US Military

83 views
Skip to first unread message

Torrance

unread,
Jul 16, 2011, 10:27:56 AM7/16/11
to SANS Internet Storm Center / DShield
Hello, recently getting ominous returns from prviously visited sites
such as pajamasmedia.com/instaupundit
NOT the usual Bluecoat exeption for blogs, pr0n, downloads, etc we're
used to. Here is the error:
"The SWA CYBER CENTER has been directed to block this site due to
possible malicious content.
If you feel this is in error, please contact your local SERVICE DESK"
SWA= South West Asia, where I am stationed.
VirusTotal scan <http://www.virustotal.com/url-scan/report.html>
returns 15 clean and 1 suspicious from wepawet.
Avira Clean site
BitDefender Clean site
G-Data Clean site
Malc0de Database Clean site
MalwareDomainList Clean site
Opera Clean site
ParetoLogic Clean site
Phishtank Clean site
TrendMicro Clean site
Websense ThreatSeeker Clean site
Wepawet Suspicious site

What does it all mean? Nobody will give me a clear answer. Thanks
all.

Zijyfe Duufop

unread,
Jul 18, 2011, 10:08:33 AM7/18/11
to iscds...@googlegroups.com
2 things:
If it was indeed the SWA Cyber Center, this has nothing to do with the us military, and
are there any correlations between the sites that it blocks other than that they were previously visited?  Maybe the kind of content on the site, or the i.p. range they're in?


--
Need IPv6 Training? See http://www.ipv6securitytraining.com . IPv6 Security Training

To unsubscribe from this group, send email to
iscdshield+...@googlegroups.com
For more options, visit this group at
http://groups.google.com/group/iscdshield?hl=en

The Carrots

unread,
Jul 18, 2011, 3:49:08 PM7/18/11
to iscds...@googlegroups.com, SANS Internet Storm Center / DShield
Wepawet is a service where you can upload a flash file or PDF (or provide a link) and it will get scanned for malicious content like embeded obfuscated have scrip in pdf's

Do they use any syndicated advertising? There was a wave of that recently.

What's the URL of the block notification ?

Sent from my iPhone

Torrance

unread,
Jul 19, 2011, 7:03:08 AM7/19/11
to iscds...@googlegroups.com
Hello the URL of the block notification is that of the site: http://pajamasmedia.com/instapundit/ .  OK the obfuscated scrip kinda makes sense because I had the site scanned by wapawet and it returned some mildly obfuscated code but I thought it was JAVA.  However, on another site that returns the same error, volokh.com, Virustotal returned 16 clean tests including wepawet.

Torrance

unread,
Jul 19, 2011, 7:17:53 AM7/19/11
to iscds...@googlegroups.com
Hello the only correlation between the sites that I can think of is they are all rightish, libertarian type blogs.  Instapundit.com and volokh.com being law professors.  www.realclearpolitics.com and http://www.redstate.com/ being news aggregators.  I am intrigued by your assertion that this has nothing to do with the us military, as the SWA Cyber Center is run by military contractors:
 
Reply all
Reply to author
Forward
0 new messages