Following up on a suspicious redirect I encountered and hoping someone with malware analysis/sandbox experience can help me understand the results.
I accidentally visited a typo domain while trying to go to indianasheriffs.org.
The typo domain redirected me automatically to:
yfdabv11[.]com/?dn=indianasherrifs[.]org&accid=228450093&spfwd=1&spmsg=nschttp%3A504
I did not enter my name, email, password, card information, or other personal information. I also don’t remember clicking/interacting with anything on the redirected page.
I checked Opera GX afterward:
No downloads occurred around the time of the visit.
Camera, microphone, location, notifications, clipboard, automatic downloads, etc. were not granted site-specific permissions.
Browser history appears to show the redirect followed shortly afterward by the legitimate site.
I did not install or manually run anything.
What concerns me now are the results when checking the redirect/domain through security-analysis services.
I’m seeing roughly the following:
Hybrid Analysis: Threat score around 69
BForeAI: 100% malicious
Criminal IP: Clean
URLScan.io: No classification
CleanDNS: No result
VIPRE: No result
ScamAdviser: Unsure
Hybrid Analysis also shows a section for “Related Files”/“Dropped File,” although the file itself appears to say “No specific threat.”
I’m hoping someone can help me understand a few things:
What is likely causing Hybrid Analysis/BForeAI to give this domain such a high malicious/threat score while several other services don’t classify it as malicious?
Does Hybrid Analysis showing a “dropped file” mean the website attempted to drop that file onto visitors’ computers, or could this simply be a browser/cache/temp artifact created inside the sandbox?
Is there anything in a Hybrid Analysis report that would specifically indicate a successful browser exploit, drive-by malware download, infostealer, RAT, or executable payload rather than simply suspicious redirects/advertising behavior?
Since my actual Opera download history shows no downloads and I didn’t execute/install anything, how concerned should I be about the original visit?
Is there any way to safely reconstruct what the page displayed at the time? For example, running the typo domain/full redirect URL inside an isolated VM/browser sandbox and capturing screenshots and the redirect chain?
I’m particularly interested in determining whether this was primarily malicious/low-reputation redirect infrastructure versus a website actually delivering malware to visitors.
I don’t plan on revisiting the domain from my normal computer.
Thanks to anyone familiar with Hybrid Analysis, URLScan, browser exploitation, or malicious redirect infrastructure who can explain what these results actually mean.
Source: r/techsupport · by /u/Foreign_Collection_5