Translate

3/03/2014

suburbangloves.us INFECTED (IP: 31.131.31.37):
Newly registered (27/2/2014) with STYX EXPLOIT (Request)
CVE-2013-0422 & CVE-2012-1723 (MALICIOUS DRIVE-BY-DOWNLOAD) HEUR:Exploit.Java.Generic (Ukraine & Atlanta, UNITED STATES)


MALICIOUS SITE: HEUR:Exploit.Java.Generic
CVE-2013-0422 & CVE-2012-1723 - Styx Exploit

MALICIOUS DRIVE-BY-DOWNLOAD

DOMAIN:
http://suburbangloves.us/
  • https://www.virustotal.com/de/url/0f6259a4a69dff3c944152fea3de2851e3b5ef01fb61496147a3d6dadfd614b0/analysis/1393800305/
http://suburbangloves.us/QqzUdhQGUQQPGvzO
  • https://www.virustotal.com/de/url/8fb30cd5ff21e6e7e6b431c6431ccddcc42e4152bfd1b90444007240b25ae68d/analysis/1393794468/
  • https://urlquery.net/report.php?id=9744021
--->
http://suburbangloves.us/QqzUdhQGUQQPGvzO/i.html
  • https://www.virustotal.com/de/url/9c92ac7cd39719f5fa343ec013820ca40aa4d55846ab01a7afaab2c3eb670f94/analysis/1393794963/
HTML
  • https://www.virustotal.com/de/file/1e645c21dd7a80086a30a4ab4acc9fe78f1af174e48db2473765987633235f36/analysis/1393789188/
--->
http://suburbangloves.us/QqzUdhQGUQQPGvzO/yTMLH.html
  • https://www.virustotal.com/de/url/5bd4347667f2df453c91ba18ad66f305cc87326a41edf504ceac218d7750ee8e/analysis/1393795068/

DRIVE BY DOWNLOAD FROM:
http://suburbangloves.us/QqzUdhQGUQQPGvzO/gKJRbJIU.jar
  • https://www.virustotal.com/de/url/e0e0e0f255765c8591d68997361d9fff0181e03c4255dfa6e9ce011426ce1f09/analysis/1393794808/
HEUR:Exploit.Java.Generic - CVE-2013-0422 & CVE-2012-1723
  • https://www.virustotal.com/de/file/7b4e78e8d40735130f125f2a7f555685541e512a2e25a82cf30fdf0ecb66fa22/analysis/1393794812/
IP:
http://31.131.31.37/
  • https://www.virustotal.com/de/url/e100f0c610570e43a4c8e36054a370e07da32459804da03a6e581adccb2357a4/analysis/1393803636/
  • https://www.virustotal.com/de/ip-address/31.131.31.37/information/

FOR CVE-2013-0422, PLEASE READ:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0422

FOR CVE-2012-1723, PLEASE READ:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1723

FOR FULL REPORT SEE .txt ICON: 

Document hosting: UploadEdit.com
You Will Be Caught...Make no Mistake about it (4 Days online, and already mistaken...)

Keine Kommentare:

Kommentar veröffentlichen