What's up with a website - Need internet expert

This thread can be used for any website problem.

The one at the moment is the Modal Electronics Website.

Need the help of someone who understands the internet well. Perhaps you work with it for your job.

I ran a website check from NordVPN and it says it’s clean :

I am having no problem accessing their website directly, but other people are having various issues. It definite goes to a bogus place when the address is found with a Google or Bing search.

Check out the three posts here ( and ignore the fourth poster ) :

the website works just fine, for a second it was blocked by ublock origin under badware risk list, I assume someone managed to alter their dns config and redirect to something spammy, but seems to be fixed.
the website registered with a chinese domain registrar, so it could be that the registrar servers were altered and been restored once discovered.

4 Likes

Those sites can very occasionally note something off but aren’t authoritative about a site being “clean”.

We can guess at the culprit here but it’s hard to build the model retroactively when it’s no longer presenting, without more forensic evidence and it seems to have been cleaned up from the hiccup.

One thing you can do if this is an issue would be to try whatever the most reliable public DNS server would be in your area over your ISP’s. I’ve been meh on Google as a company lately but they offer their own, I think Cloudflare also offers their DNS resolving etc.

yep yep, could be DNS spoofing - Wikipedia

1 Like

Not true.

I just generated this with Google :

DON’T CLICK ANYTHING HERE !

REMOVED

I will take this down in a few hours as I consider it potential hazardous, unless a moderator does it first.

1 Like

Well, you didn’t provide any such link for us to know, just a screenshot of a URL.

So, what were you searching for in Google that got you there?

If people are to trace what’s going on, we need somewhat more details to build whatever model.

I checked this from the link on E’nauts and it failed once and worked once.

Google or Bing – Modal Electronics – and click in the sponsored link.

You’re providing a cached link, stored by Google. If whatever DNS source it is using was poisoned, it will continue pointing from Google to the malicious site.

Yes but malicious ads are a constant problem, it’s not necessarily posted by Modal themselves.

If you’re only seeing this via a “sponsored link” and not directly you’ve got a completely different vector that may have been exploited. Just because the link suggests Modal doesn’t necessarily mean that the encoded metadata will be sending you there…

It’s also possible that there is/was a malicious URL that was added covertly to their site, but if this is coming from an ad campaign I wouldn’t be surprised if there was a redirect set up in the process to present you with one URL string but send you to a completely different site. One of these days I really ought to set up a campaign for my own understanding of the process.

Anyway, narrowing down the scope of the problem helps nudge towards what is more or less likely to be the case.

https://wheregoes.com/trace/20245556778/

Error: The response filesize was too big to check for JS and meta-refresh redirects. We are assuming we have arrived at the final destination. We do recommend reducing your HTML DOM size.

Interesting, the URL submitted to the adwords campaign may have been structured in a way that short-circuits some simpler analysis and would allow one URL to be visible but preserve a local redirect that takes you to the completely different site.

Still the possibility that their site hosting or some forums software had also been hacked, but I don’t really have the time to poke around there and the level of energy and possible result to come from combination of site hack and adwords campaign, just seems a lot of coordination even if a semi-automated process for both.

Decoding ved parameter just gives
{
“type”: “22”
}

sqi parameter - site quality index? I don’t have a ton of info on how to decode usg.

I imagine there may be a malicious redirect (javascript or otherwise) encoded in usg and pushed to you when you click.

Malicious ad buys can encode simple scripting in a way that Google is often but certainly not always smart enough to recognize and while the modal URL is valid, and DNS intact, the entirely different URL and whatever minimal script to point you there are hidden, encoded in Google’s arcane parameters until they are served to your browser.

1 Like

Someone found the same issue with their site-

Separately https://isc.sans.edu/diary/How+Malware+Campaigns+Employ+Google+Redirects+and+Analytics/19843/

Ok, this maps enough to your question that I’m going to quit looking in further and get some real work done :smiley:

1 Like

This was real work too. Send me the bill. :lollipop:

Thank you thermionic !

It still fails from Google for me, but as I’ve already concluded it’s not directly a problem with Modal’s web-site. I am no longer going to post on this.

I originally heard of this problem from an article in Synthanatomy.

1 Like