Malicious Domain Request 22 - ro9.biz

Hello everyone,

Recently I tried to clean my saved passwords history. Found one old entry and tried to enter the site (to confirm I no longer need it). I am using Google Chrome.

This is the page: http : //w ww . p2w - cod4 . yoyo . pl

Then i had few redirects to a different domain. I closed the card immediately. Then I switched into incognito mode and tried again (as there are no extensions) to check. Now Norton Security has set a pop-up that I have "Malicious domain request 22" from "ro9 . biz". On the internet I found several entries that this website is a malware and IF I click somewhere it may pop some notifications in my browser (but I didn't). Since I immediately closed the tab in normal mode I have no entries in my browser.

This is a screen what I had in incognito mode:

In incognito mode Norton didn't go any further and stopped at ro9.biz website.

Steps I did after closing browsers:
1) Quick scan by Norton -> No items,
2) Full scan by Norton -> No items,
3) Power eraser by Norton -> No items,
4) Full scan by Malwarebytes -> No items,
5) I checked that I have no entries in "Notifications menu" or similar, no cookies, no new extensions,
6) No new applications in autostart, services etc.

Why does Norton in normal mode (not Incognito) allows to redirect to certain malware sites multiple times?
Should I be worried now?
Is it possible that this site (after all redirections) somehow steal cookies (session IDs)?

Thanks for any help.

My Norton version is: 22.21.1.151

[Edit: Removed hyperlink to a potentially malicious page to conform with the Participation Guidelines and Terms of Service]

If the translation of your image in the first post is the same as shown in bjm_'s post saying  'No Action Required', it means that Norton did its job and blocked access to your system from any malicious behaviour.

 

How to install and run a scan with Malwarebytes (Guide)
https://malwaretips.com/blogs/scan-malwarebytes-anti-malware-2-0/

https://www.malwarebytes.com/malvertising/​​​​​​​
​​​​​​​https://www.malwarebytes.com/browserguard/
https://forums.malwarebytes.com/forum/108-malware-removal-help/

 

Thanks for help.

So I got redirected to some random page (Immediately closed card). I'm clean. Is it possible that some end page will steal cookies (I didn't click any image or buttons)?
Because then i should visit all sites, then logout and login or even change my password.

 

http://www.p2w-cod4.yoyo.pl

landed on

extension://fnpbeacklnhmkkilekogeiekaglbmmka/content/ui/blockedPage.html?originalURL=https://vassal-jewish.xyz/click.php?key=cd87grwf51wf5mpqatgl&Bid=0.015&src=4cd0f5d0dcf60afe3fc7a4fd54baa095&keyword=yoyo&category=109&cxid=639266&blockPageType=IPS&IpsSignature=26823

Web Attack: Malvertisement Website Redirect 3
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=26823
Continue to the site
png_9880.png

http://www.p2w-cod4.yoyo.pl

landed on

https://tco20.proasdf.com/v3/s?c=&s=it-1500&d=yoyo.pl&k=raas.econ&r=&t=1&u=&v=&x=&y=&z=&pz=&f=1&tk=705c6110ce480182694578bb5ca53155&q=raas.econ.q00_age_gender


png_9876.pnghttps://safeweb.norton.com/report/show?url=https://tco20.proasdf.com/v3/s

as test: Intrusion Prevention Off

http://www.p2w-cod4.yoyo.pl/


png_9874.pnghttps://safeweb.norton.com/report/show?url=http://www.p2w-cod4.yoyo.pl/

http://www.p2w-cod4.yoyo.pl

https://sitecheck.sucuri.net/results/www.p2w-cod4.yoyo.pl

landed on  

https://news-central.org/Cmvm9uB1kgBojhsC0HVv7gUF2e5w6d4Mewu3agf43po/?cid=zr68788c1390f511ebbc9e0a313b012243b95aeb0466b846c79b96ae2510470c0e054721048b6df98e1c&dom=yankee-you-p5fd86ksa

https://safeweb.norton.com/report/show?url=http://melanthios-ana.com/zcredirect

Malicious Site: Malicious Domain Request 22
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=31350

https://news-central.org/

https://sitecheck.sucuri.net/results/https/news-central.org

https://safeweb.norton.com/report/show?url=https://news-central.org

Remove News-central.org pop-up ads (Virus Removal Guide)
https://malwaretips.com/blogs/remove-news-central-org/

Hi pete_pl,

Please have a look at the following article: Remove Ro9.biz pop-up ads (Virus Removal Guide)