Translate

Posts mit dem Label HEUR:Trojan.Script.Iframer werden angezeigt. Alle Posts anzeigen
Posts mit dem Label HEUR:Trojan.Script.Iframer werden angezeigt. Alle Posts anzeigen

3/29/2014

RECENTLY (RE-)DETECTED:
afristyle.com infected with HEUR:Trojan.Script.Iframer
IP: 160.124.112.100 - SOUTH AFRICA



MALWARE: HEUR:Trojan.Script.Iframer
DOMAIN:
http://afristyle.com/
  • https://www.virustotal.com/de/url/94e4f0d5dec56125cc4ac81ecd1aea5438e8ee9191f9a1ddee5729b370a5ee3f/analysis/1396113676/
HEUR:Trojan.Script.Iframer (PUA, document write)
  • https://www.virustotal.com/de/file/61b5f2266af649aeb40b3c12cb9b437da4c9b09492cff6aaf2fe4c33f46401e0/analysis/1396113489/
IP:
http://160.124.112.100/
  • https://www.virustotal.com/de/url/34dfd6f154e8f0f124b31235af491ff951386a432cf009980d5abed411171b24/analysis/1396114396/
  • https://www.virustotal.com/de/ip-address/160.124.112.100/information/
--->
http://find.uk.to/dns.htm
  • https://www.virustotal.com/de/url/9882d00fcdca159baba47dd3f0b38cb7277532978e54e483d51da98599153adf/analysis/1396114311/
  • https://urlquery.net/report.php?id=1396113767846

2/14/2014

ABBA (S.O.S.) & New Malware Code:
www.abba.it & IP 79.135.167.28
Trojan.JS.Iframe.ahh & Trojan.JS.Iframe.ahi (PUA) (ITALY & POLAND)






ABBA MALWARE AT LEAST SINCE 2012: HEUR:Trojan.Script.Iframer (PUA) (RBN 351, ITALY & POLAND)


http://www.abba.it/
  • https://www.virustotal.com/de/url/84645d2eca6550ebd7c47540670934f2383b374162aac5210fe7b6be7e5704e9/analysis/1392389097/

INFECTION:

HEUR:Trojan.Script.Iframer (PUA)
  •  https://www.virustotal.com/de/file/3f6d4bcd51b2a294897c1e76402fc2ec956a411ac92acbe7f89029748eae3522/analysis/1392389334/

The complete report (.txt) can be seen here:

Document hosting: UploadEdit.com


SINCE 2009: www.cafi.it
Infected with Malware: Malicious Iframe Injection
At the Moment: HEUR:Trojan.Script.Iframer (ITALY & UKRAINE)


MALICIOUS DOMAIN ALREADY SINCE 2009: HEUR:Trojan.Script.Iframer (RBN 422) (UKRAINE)
http://www.cafi.it/
  • https://www.virustotal.com/de/url/7bd6d2f5f61ade1dcfe6c3357fd48b812d1f40ef8d54b3feae0a71cb831dd2b1/analysis/1392383368/
INFECTION: 
HEUR:Trojan.Script.Iframer
  • https://www.virustotal.com/de/file/3510b819f8d1d209bb267f3a721f9cb040fc2c609412e7ace7f2dcd75528e67d/analysis/1392384000/
Mal/Iframe-F
  • https://www.virustotal.com/de/file/6eb573fba0944e608d57dc882860149f14bdb2368a295ac19e93f7e6a0072386/analysis/1392383703/
Malicious iframe injection
Javascript associated with malicious code
  • https://urlquery.net/report.php?id=9433018
--->
http://91.207.61.32/.r/.fi/index.php
  • https://www.virustotal.com/de/url/9d80e5be6628f7734d3fd816c391733b5c4e491c2f96818e22738b8a9c2ed5c7/analysis/1392384629/
  • https://urlquery.net/report.php?id=9433214

12/27/2013

Category MALICIOUS DOMAIN: anadoluerenleri.org - HEUR:Trojan.Script.Iframer - Exploit Kit Blackhole (Turkey)

MALICIOUS DOMAIN:

anadoluerenleri.org
  • https://www.virustotal.com/de/url/e16489216d92994fbac3bbcb9cb37d95d0d2cd1e4fb010be8b34728cceaccbae/analysis/1388152745/
INFECTED WITH: HEUR:Trojan.Script.Iframer
  • https://www.virustotal.com/de/file/30a611161ae8c4a3d06ca0052795ce7adc378dbf09405536f98bb9a1697ee3b9/analysis/1388153111/
  • https://www.virustotal.com/de/file/67c43a96d2475e927f5bf7d98796bef0f899031983ff1cdf5c9d564ca32970bc/analysis/1388153087/
  • https://urlquery.net/report.php?id=8568895
---> REMOTE DESTINATION (DOMAIN)
rcmeewprehhjewea.info
  • https://www.virustotal.com/de/url/412467cad9e07b697b7dfb855b20bec7f27f603e7e722c6bc49bde31551e4b3c/analysis/1388153380/
SPECIFIC LINK:
rcmeewprehhjewea.info/in.cgi?14
  • https://www.virustotal.com/de/url/a7da15f9a7b751e57c085195fde2dfb5ae73516edd7ce5c33c136c90e79298e3/analysis/1388153366/
Google Safebrowsing:
  • http://www.google.com/safebrowsing/diagnostic?site=anadoluerenleri.org