Malware on Airtel Smartbytes page

  • Thread starter Thread starter Sushubh
  • Start date Start date
  • Replies Replies 13
  • Views Views 4,144

Sushubh

Admin
Staff member
Messages
406,949
Location
Gurgaon
ISP
Excitel
Airtel
Be careful while opening Airtel Smartbytes! : india

Tried it. Can confirm.

iEsMWVh.png
 
It's a very old malware they have. I have noticed it like 1 or 2 year back.
 
Can anyone check this?

My AV caught error when browsing ICICI bank yesterday.

(Its just phishing so probably harmless to access. But do not give any details and be careful)

https://pdf.icicibank.com/1266161/NSG7.html

AV result (clamav)
NSG7.html: Sanesecurity.Phishing.Bank.3279.UNOFFICIAL FOUND
 
Last edited:
Yes lots of code.. but does ur AV detect anything?

Could be the sanesecurity definitions that I use causing false positive.
 
I have started this topic on reddit with the link given on the very first post of this thread.

It redirected me into a series of spam and malware websites (that's Airtel's fault, it seems). Half of which it was undetected by Virus Total. Only one or two websites had reported as malware and phishing websites, claimed by VT. Just a mixture of malware-cum-phishing website forced redirects (mostly websites with .win domain). There's also a YouTube video to show the same:


Source
 
Last edited:
I have started this topic on reddit with the link given on the very first post of this thread.

It redirected me into a series of spam and malware websites (that's Airtel's fault, it seems). Half of which it was undetected by Virus Total. Only one or two websites had reported as malware and phishing websites, claimed by VT. Just a mixture of malware-cum-phishing website forced redirects (mostly websites with .win domain). There's also a YouTube video to show the same:


Source

That is very well known but nothing you can't do in this case.

That's not malware in your phone, that's the pop script on the Airtel's Smartbyte Page.
 
Sorry for replying such an old post, but when I view the source of Airtel Smartbytes website (which I used to check available data balance), it was injected with the adware s3.amazonaws.com. Source link is given below (adware link is on the 50th line):

view-source:122.160.230.125:8080/gbod/#

That's why it got redirected to such an adware upon going back.
 

Top