For the last four days, my anti-virus software has been blocking a possible virus when I visit some popular news sites. The URL flagged as a virus is a subdomain of eclampsialemontree.net that has a long string of random characters and looks highly suspicious. A report on VirusTotal indicates two anti-virus providers are blacklisting that domain as a malware site.

The latest site where I encountered this virus alert was a story on Stars and Stripes. I'm not embedding a link for obvious reasons, but it has the headline "Veteran, one of 4,200 mistakenly declared dead by VA, feels 'resurrected.'"

In the Google Chrome developer console, I can see that when the story is read, the URL is being loaded in an XmlHttpRequest by this JavaScript code on the news page:

<script src="http://s.ppjol.net/lightbox/pp4.js"></script>
<script>
if (!navigator.userAgent.match(/StripesApp/i)) {
  var pp = { client: { config: { 'zone':"-jmtl7NTsKXjcoZnYuS2qB", 'mode':"universal", 'debug':0, 'precheck': function(){ return 1; } } } };
}
</script>

This code is provided by Press Plus, a company that manages newspaper subscription paywalls. I think the purpose of the script is to superimpose a box above the story that urges a reader to subscribe to the site.

The script does not have any reference to eclampsialemontree.net, so I don't know why it is attempting to make a connection to one of its subdomains.

I've encountered this 24 times on different news sites. I'd like to figure out why it's happening. I post a lot of links to news stories on the Drudge Retort and I can't link to a site I believe might have been compromised by a virus.

-- Rogers Cadenhead

Comments

Happens to me too. Newsinc.com , a site with sensationalist news/media that my 10yr old has visited is hosting frame content from eclampsialemontree.net


 

I'm getting the same behavior when I visit www.DallasNews.com. I'm using Eset NOD32. If I try to visit their sports page, sportsday.DallasNews.com, I get a popup telling me I've used up my free visits.


 

Hello Roger!

You should activate moderation or spam check on your blog cause it seems that spammers are getting through.

Best regards,
a reader.


 

Dear Applicant,

We give loan to private company and individuals. You can find some vital information about the loan we offer below. In getting a loan from our company, there are some information we need to pass across to you before we can proceed to the application process . INTEREST RATE: In the loan we offer, we do charge 3% Interest rate . AMOUNT GIVEN: We Give Out A Minimum Amount Of 1,000.00 to A Maximum of 100,000,000.00 INFORMATION NEEDED: As for the information needed, you will need to fill an application which contains your personal information and also the loan information, this will help us give you a full documentation of the loan terms and agreement contract which you will be expected to sign and send back to the company for approval if satisfied. Email Us: (paulhutt02@gmail.com)

If you are interested contact Via: paulhutt02@gmail.com and fill out the below loan application form.

Loan application form:
Full Name:....................
Country:.....................
State:..............
City:..............
Sex:.........................
Phone Number:...........
Loan Amount :...........
Monthly income:..........
Occupation:................... ....
Loan Period:....................... ................
Purpose of Loan:......................... ...........
E-mail address:...................... ................
Have You Applied Before?....................

We awaits your urgent application form to be filled ok. Email Us: (paulhutt02@gmail.com)

With Best Regards.


 

Are you in debt, do you need a new house, car , payment for mortgage, repair or re-financing , without debt review, are you
looking for Company to trust for all your financial assistance and debt clearance, come to a company that has your
interest at heart, we have come to clear your debt and help you have a pleasant Christmas holiday
and debt free new year, we give loans of any amount for just 2% interest rate, we give from R30,000 and above for 2-35
years repayment plan, we do not check your credit history, we give loans to both blacklisted and clean record applicants,
contact us now and end your misery in just 24 hours, contact us now on email: thomasloancompanyplc@gmail.com


 

Add a Comment

These HTML tags are permitted: p, b, i, a, and blockquote. A comment may not include more than three links. Participants in this discussion should note the site's moderation policy.

:
:
: