Author Topic: 91.212.41.91  (Read 3642 times)

0 Members and 1 Guest are viewing this topic.

May 29, 2009, 05:03:26 pm
Read 3642 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3323
obfuscated iframe directs to feruchiman.ru /oi/in.php
Code: [Select]
bestfindahome.cn/mecht.html
startdontstop.ru/feriminet.html
startdontstop.ru/mainstart.html

contains pdf and flash exploit
Code: [Select]
feruchiman.ru/oi/in.phphttp://wepawet.cs.ucsb.edu/view.php?hash=b96048d72be4f393de5aadb53af80cf1&t=1243499758&type=js

Code: [Select]
feruchiman.ru/oi/its/0.pdfhttp://www.virustotal.com/analisis/38c418f7445e26ef279c08a9374419bf2204fe0db7ca6f32210388802e584ba0-1243616342 10/40

Code: [Select]
feruchiman.ru/oi/its/0.swfhttp://www.virustotal.com/analisis/07149d60b07b1c967847e303ecd6007e4c1172d0b937639c99bcac23fbced906-1243616353 4/38

Code: [Select]
feruchiman.ru/oi/load.phphttp://www.virustotal.com/analisis/e51515a30bb1c6ad7b344c0096afca73a949d3f0e3ecbf9f03ab0479780bb0a5-1243499065 2/40
Ruining the bad guy's day