Author Topic: 195.88.144.99/194.8.251.160 - eleonore exploit kits  (Read 3996 times)

0 Members and 1 Guest are viewing this topic.

May 17, 2010, 03:03:58 pm
Read 3996 times

eoin.miller

  • Sr. Member

  • Offline
  • ****

  • 179
Looks like an eleonore exploit kit(s).

195.88.144.99 - nuyamnyam.ru www.updatemicd.in
194.8.251.160 - dfhjdfst.com medicinada.com

PDF exploit here:
http://medicinada.com/usaa4803/pdf.php

Wepawet report on PDF:
http://wepawet.iseclab.org/view.php?hash=1704d2d08983519a179b6c266917bfa1&type=js




May 17, 2010, 03:57:07 pm
Reply #1

philipp

  • Special Members
  • Sr. Member

  • Offline
  • *

  • 218
Code: [Select]
200 http://medicinada.com/usaa4803/
200 http://medicinada.com/usaa4803/index.html
200 http://medicinada.com/usaa4803/index.php
200 http://medicinada.com/usaa4803/install.php
200 http://medicinada.com/usaa4803/load.php (MD5: 613b0104901655e5b9156bac46fc50d6)
200 http://medicinada.com/usaa4803/pdf.php
200 http://medicinada.com/usaa4803/stat.php
200 http://medicinada.com/usaa4803/i/
403 http://medicinada.com/usaa4803/load/
200 http://medicinada.com/usaa4803/i/1.php
200 http://medicinada.com/usaa4803/i/index.php
200 http://medicinada.com/usaa4803/load/load.exe (MD5: 613b0104901655e5b9156bac46fc50d6)

May 17, 2010, 04:05:58 pm
Reply #2

eoin.miller

  • Sr. Member

  • Offline
  • ****

  • 179