Translate

Posts mit dem Label Hidden Iframe werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Hidden Iframe werden angezeigt. Alle Posts anzeigen

4/10/2014

Potentially MALICIOUS ADs:
bellroy.com (IP: 54.236.92.225)
risking with
HIDDEN Iframes (W32.HfsIframe)
and Microsoft Internet Explorer remote code execution via option element


FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain bellroy.com in your AdSense Dashboard. See the following Report why:


MALICIOUS ADVERTISER: 
HIDDEN IFRAME(s) & 
Microsoft Internet Explorer remote code execution via option element

DOMAIN:
http://bellroy.com/
  • https://www.virustotal.com/de/url/c98b0274361f078ffe11c672882a44deea265179edb5c6fa0602d63080855968/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/67b5a8555f0660f5cea968abbbe32c48a92b6c0cb1782c682a0bb7d35f2439cd/analysis/1397146549/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->

AD-LINK:
http://www.googleadservices.com/pagead/aclk?sa=L&ai=CGfswyL9GU6j-NIuoiga4sYDQCouup8sGi_S0sYgBo5WpvzgQASCOwJQjUJeJzE5guwOgAd3f68sDyAECqQI_TRhS36CvPqgDAcgDwQSqBIsBT9BrjS7o2Hx01Y0JFiIuwvJ1xe9IjZ3AaQviQnug8Np1m1Lub00UCac2hzu_KqEdA3aCF6v0DESTEaRR-1SjYlNxE2mKIljXjfcmAgj4IJnE_mEbmdov7A_Top1ov2PE0Cm3JltzAOkli0GYOFPDLlmdDDZfXT2fFSIbEi-AgySr64NOLCIbYqODF4gGAaAGAoAHi6CUNA&num=1&cid=5GjrqWA5Hr9KASVQwZCWupTr&sig=AOD64_1_pgpU0nS6Jm4kbl0tCan3rcz2HA&client=ca-pub-5585202032329389&adurl=http://bellroy.com/wallets/note-sleeve-wallet&nm=2&mb=2&bg=!A0RJckn2eYHUnAIAAABGUgAAACcqAPHBZ1R_GZZ-qskVhAC1RCaSH8E7P1WWZC0O5x_RfOeSlUkxeJvIMszsmy3sXPqRsDlNy8wF68FONASqnu6VRxJ-s-NpHWsQ1GS7blV93HhI3unMwwLWf3jO_ggQ1uDpL5_XK5lofwEA5P2icYwOYX-diVH7uhcjdcVDH0WnnUDwsfalxoHuio6rkHLlVZEw0K_n8FBECRILAC_D7YNm3YixQnPoAup1vg7QEcYLoGraugw_6A2qJro2Z8bmpX0mbatP_HXSBMdhAiO9S4pffic21NrkmjGVx-d_c9TBhi1Tj4BMHIOEuAFJr7PX2F7yuuWu
  • https://www.virustotal.com/de/url/95f54e683c7aa90bcff2516c4203b1eab34ab0773398e57f1df39494d6bfa9da/analysis/1397146003/
W32.HfsIframe
  • https://www.virustotal.com/de/file/5a84faf5f6aca07d4390a9b5cfccc29512b29edb295113d7a6f81dd8c85e0028/analysis/1397146289/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->
Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=1397146071040
  • https://urlquery.net/report.php?id=1397146084651
--->
http://bellroy.com/wallets/note-sleeve-wallet?gclid=CJGghbqm1r0CFbFFMgodI1QA3w
  • https://www.virustotal.com/de/url/415b1b40a688e6db53001d576b04991a469967e8b17f5327f591942b0ec5b423/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/fbf1f3b0f36895ff64f2ed8270a6058d912395b6fe94a596b7f0e04381422a90/analysis/1397147003/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->
Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=1397146245634
  • https://urlquery.net/report.php?id=1397146261020
  • https://urlquery.net/report.php?id=1397146282006

IP:
http://54.236.92.225/
  • https://www.virustotal.com/de/url/17c875d298cbb4a685465b5dfbd5f3ae5097b78a8fa58184f224a872eec7d4f3/analysis/1397147591/
  • https://www.virustotal.com/de/ip-address/54.236.92.225/information/

HIDDEN LINK TO:
http://carryology.com/
  • https://www.virustotal.com/de/url/85e70248597bc714f3eac0644ff669c2680af8b6a50b23d34420e54e0f9bd902/analysis/1397147301/

4/08/2014

Potentially MALICIOUS ADVERTISER:
Heuristic.LooksLike.HTML.Suspicious-URL.K
@
gaastraproshop.com (m.gaastraproshop.com)
IP: 65.52.130.250 UNITED STATES

FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain gaastraproshop.com (m.gaastraproshop.com) in your AdSense Dashboard. The Site is potentially Blacklisted. See the following Report:


POTENTIALLY MALICIOUS ADVERTISING DOMAIN:
Heuristic.LooksLike.HTML.Suspicious-URL.K & HIDDEN IFRAMES

DOMAIN:
http://www.gaastraproshop.com/
  • https://www.virustotal.com/de/url/8fe4129403e2f8a3329f8e8c2c030a8e071aa0ca416e83db22bbf2647a9b9354/analysis/1396956156/
HTML (before REDIRECTION) Heuristic.LooksLike.HTML.Suspicious-URL.K
  • https://www.virustotal.com/de/file/bd2bbbc521c2ef59397a0d0094451a2f1c978c88ee3f408a796071a58a733476/analysis/1396956097/
HTML (after REDIRECTION TO: http://m.gaastraproshop.com/ )
  • https://www.virustotal.com/de/url/9b672b89952372844701c6eaee854ac53baed519cf854c2d76f7027e8509ac46/analysis/1396956311/
  • https://www.virustotal.com/de/file/5a7ac6c9a4573c03f9d3b78278854f8eeb77300b41013769849f9593b61cdc10/analysis/

AD-LINK:
http://www.googleadservices.com/pagead/aclk?sa=L&ai=C9_qImM1DU5zaMMyR7ga_pIGgD-7TzuYDzuLHuJsBwI23ARABII7AlCNQuuWsjQNguwOgAczZxPUDyAECqQJouv3HAA-3PqgDAcgDwQSqBK0BT9BVRjDmVncwPOaYlYqDgq5ewlrE62ZKg0EI3bGzSTS2RY4AcjI1uPQNsHaT4rugdrGcIj5NrDkcP7WvV3x2WuALeS2pfl45Vy5x8WsjjQJyAGpQLLToRLzbxcQM41r1VIRWE8sXrd471wq5qDA1D1yV2v7JUSCrkTyQapMs3-HduhxiXs_1faUi_uZDXGoSpta2LFNFHiVzbqL7spmvDb14LM8BdBc3Ht1CYHmIBgGgBgKAB5ymuwo&num=1&cid=5Ghek0AXvKdmiT_PaZgyrXhR&sig=AOD64_1HNWVDpsJ2tiouym8BUaG8D7D4nw&client=ca-pub-5585202032329389&adurl=http://www.gaastraproshop.com/com-en/&nm=3&mb=2&bg=!A0QdcMC5dYUeWQIAAAA5UgAAACwqAOEto0uFWoyzbF9BgLpTZd0j0HlH_C56hY4NLvc3NtowaaH-Z-csGgTuThLZ2700ImAxJCtXBWy07lw2lhyW729LbQpRbKOUhBOCgNPTzNU7gGGfUbNk7f1Es-R1OT2rxWGFmICxmADsYZbJkCp3x90QW9x_krZl8PbIDV5TojB9Z4tmta85i7Np_800PxgiPJJfwWvSEdIldac4iEnohF9kF7b9tuMjUDC-jxzvmThXXObWG5HuPVidMyu5kw1D6sjILopgRn4ifnP6aV0gn8heXTWUH6sXVSlhTfbA-94Jv2Y
  • https://www.virustotal.com/de/url/62eb0a95606957e05b738baee9c886cb70a5e34c5e23659bbf4d96dc14ca3df1/analysis/1396955224/
(HTML-SRC) Heuristic.LooksLike.HTML.Suspicious-URL.K
  • https://www.virustotal.com/de/file/567b8090d9678ab59051c8039a8ee4db6219e30ddc833fc417e74ce75d051dd1/analysis/1396955699/
URL AFTER REDIRECT:
http://www.gaastraproshop.com/com-en/?gclid=COiest_f0L0CFeY-MgodzxsAfw
  • https://www.virustotal.com/de/url/8e9706ee82cfd4bafcde4bb245ce1dd2798c2e1bb7d35e914015246b70eb1f1c/analysis/
(HTML-SRC) Heuristic.LooksLike.HTML.Suspicious-URL.K
  • https://www.virustotal.com/de/file/476be34d21b40a8ebc9eedf9bfd0b59a671735cac2517af1e007cdabf9860d80/analysis/1396955811/
IP:
http://65.52.130.250/
  • https://www.virustotal.com/de/url/153ecf2fa49f6cfa49c849cdadf0abea1ca0d4ea9d299e1ce04c837d83c498ad/analysis/1396957138/

4/07/2014

POTENTIALLY SUSPICIOUS Advertiser:
Several HIDDEN IFRAME(s) @ www.studyinteractive.org
(IP: 94.236.98.164) W32.HfsIframe

London, UNITED KINGDOM


FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain www.studyinteractive.org in your AdSense Dashboard as the Site has several hidden Iframes (See Screenshots below). See the following Report:


SUSPICIOUS ADvertiser: 
HIDDEN IFRAMES & LINK TO MW DOMAIN

DOMAIN:
http://www.studyinteractive.org/
  • https://www.virustotal.com/de/url/f3d49c88f67e594a5e2790d6b04c04386bba772e06b5bdcd610274e6dec7ad78/analysis/1396890659/
W32.HfsIframe
  • https://www.virustotal.com/de/file/b3057590ae1f538dae28ef2eddd5b949129640e22e8c7c84afa40e1c552a5fe0/analysis/1396890736/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-5BZNPB"height="0" width="0" style="display:none;visibility:hidden" --->

IP:
http://94.236.98.164/
  • https://www.virustotal.com/de/url/ddf767ca33c02f03d89c48d06d684ebfc9fd7b70d8a44a6bad3660bba2f84648/analysis/1396892016/
SPECIFIC AD-LINK:

http://www.googleadservices.com/pagead/aclk?sa=L&ai=C1Ka8_MxCU_6pOsvr7QapvoCYCJX4hcsEndDjp4QBwI23ARABII7AlCNQ6eatif______AWC7A6AB8_Da0wPIAQGpAsaE3dbr1Ls-qAMByAPDBKoEsQFP0HE28GLR59i93_uQP7nr9q4E30h6pDFBgQJbzqpCJJQQ0aDe7YvxTlGaY9pzRs8vyF1nEHdo1tEAxFx16XC4-Lgl4-fxn3hJKR0igEeXfXlRVNkv56ddmN1ZG2RsPQg-YbbQmHKkGucDnGRdtwT4iKZTWEojzb85nYybniV-WkEGRp3JQBIRR-2hTseS9CIQGQrcwP7Cz99h34GT4pyQhlUfpQWsZ4rjvxjYqb7COXOIBgGAB_WOpSw&num=1&cid=5Gj_mwym0n6HSEiehmL18tKY&sig=AOD64_3BPMMDRbXyPW9Agp98BUEmTc_g0g&client=ca-pub-5585202032329389&adurl=http://www.studyinteractive.org/online-msc-degree2/%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_campaign%3Dmsc-marketing-luxembourg-display-text&nm=10&mb=2&bg=!A0SiEbXxXfeE9QIAAABCUgAAABgqAOHJi1VYTcVszlW_XQUl16Q6RwLTV7-FnDAWCTMg7ixb-JsMj7_eP2TWBvsEjUNKn4TAMGA73MqGBwJ-w_73TLtBVo1E34m53HRZVDIFE0NQxJMKmmppdH6t3vG98-ot5NeBXD8SYUWjnS2VBK-zrqrmBfuwIxkIZvx0tvJddgQvoUdsHU6vdaRpgM7loHmZ70FOefIOOYqyz91P4jYaNIZ0otKMJdBbH1YsWRa3FQVuV3i-wQm6wp4RTQdW--qo2tCemW5HIh8nQ-TFOMZSe9RB4WL1uT4_vGbX3zhqpvnBjiM
  • https://www.virustotal.com/de/url/1d73c6f82f71c6f97a917a117f66581a541f0465632350adf6c0b8327ec6baeb/analysis/1396889946/
W32.HfsIframe
  • https://www.virustotal.com/de/file/93003317e07e1338c35800a3c63ef637fa64acb8786e3f5e5d2bdb062a8f5129/analysis/1396890437/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-5BZNPB"height="0" width="0" style="display:none;visibility:hidden" --->

URL AFTER REDIRECT:
http://www.studyinteractive.org/online-msc-degree2/?utm_source=google&utm_medium=cpc&utm_campaign=msc-marketing-luxembourg-display-text&gclid=CMGByMjszr0CFfFFMgodcxsAeQ
  • https://www.virustotal.com/de/url/1ab400460a40eb42b654e42f30b0173a413331e158774d4746cbddb6c1205d53/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/93003317e07e1338c35800a3c63ef637fa64acb8786e3f5e5d2bdb062a8f5129/analysis/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-5BZNPB"height="0" width="0" style="display:none;visibility:hidden" --->

SEVERAL MORE HIDDEN IFRAMES DETECTED:


Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

OTHER SUSPICIOUS LINK FOUND:

DOMAIN:
http://lsbfafg.com/
  • https://www.virustotal.com/de/url/b6f887a3a71940ddb1be80e110d2a44974e1140a009baaf392e745afba19a61a/analysis/1396891366/
http://lsbfafg.com/getform.js
  • https://www.virustotal.com/de/url/b6f887a3a71940ddb1be80e110d2a44974e1140a009baaf392e745afba19a61a/analysis/
http://lsbfafg.com/getform.js?id=12600
  • https://www.virustotal.com/de/url/9455bddead54d9bb28c3deba78ec01923cec20ad9172b6628a38592cea3a4d33/analysis/1396891806/

4/01/2014

SCAM OF THE DAY from:
"WIR BIETEN DARLEHEN" ("We Offer Credits")
With Greetings from Coquitlam (CANADA), Australia &...& ratgeberplatz.com

IHR SEID IN ALLE FINANZNÖTE ODER BENÖTIGEN SIE MITTEL ZU STARTEN IHR EIGENES GESCHÄFT? BRAUCHEN SIE DARLEHEN FÜR IHRE SCHULD ZU BEGLEICHEN ODER ZAHLEN SIE IHRE RECHNUNGEN?
Wir geben Kredite im Bereich von 7000 US-Dollar (sieben Tausend Dollar) bis zu 50.000.000 US-Dollar (50 Millionen Dollar) mit 3 % Zinssatz.



Füllen Sie das nachstehende Formular (ist kein Formular, nur Text im Mail) für die Anwendung von Darlehen durch:



Persönliche e-Mail-Adresse:

Name: Adresse:

Land:

Telefonnummer:

Menge, die benötigt werden:

Darlehen-Dauer:

Monatliches Einkommen:

Alter:

Geschlecht:



Sie sind Beratung senden Ihre Daten an diese e-Mail-Adresse ein: scoth_smitt@ymail.com



Alles Gute
Herr Rev Scoth Smitt (Blöder gehts wohl nicht!)
Screenshot of HOCHwürden.....

MALICIOUS: HIDDEN IfRAMES ALL OVER THE PLACE & INVOLVED IN PHISHING SCAM
http://sd43.bc.ca/
  • https://www.virustotal.com/de/url/8290fd493074a03e4b9c2e28e27d880175519bba5ec36b12f16aae864214fe44/analysis/1396302819/
http://sd43.bc.ca/Pages/default.aspx
  • https://www.virustotal.com/de/url/3430aa5e2fcb1a7be76346576a55c9179acb649e9ab39d83843e692dbf2eca0e/analysis/1396302945/
HTML: 
W32.HfsIframe.420f (WHATEVER IT MEANS REFERS TO A HIDDEN IFRAME)
  • https://www.virustotal.com/de/file/701247cb9f12329ce5558b3ceff20ab16a4f4880606b86cfe7fe474480f7299b/analysis/1396302682/
ORIGINATING IP(s) (ratgeberplatz.com again involved): Coquitlam (CANADA)
http://142.35.6.131/
  • https://www.virustotal.com/de/url/0878044af1696c27903ac4978f8113c96b1222f5461fbc8f2e9db3191934f1f1/analysis/1396304403/
http://14.2.27.4/   (Adelaide, Australia)
  • https://www.virustotal.com/de/url/3bdc4ddd451c4313001e49b924ff7ff7022ee6cec34bf8ec7b614487b5de2bf8/analysis/1396304621/

3/28/2014

Packed.Win32.Black.d (+ Win32/Injector) @:
windowssoftwaire.eu5.org
(IP: 5.9.106.214)
GERMANY



MALWARE SITE:
1 - Packed.Win32.Black.d
2 - Win32/Injector
3 - HIDDEN IFRAME


DOMAIN:
http://windowssoftwaire.eu5.org/
  • https://www.virustotal.com/de/url/cf360dffa24a58212c44d2340e2aeacac62031d1b06ac3a968f2e13edb33d41e/analysis/1396014984/
---> HIDDEN IFRAME TO
http://ads.yahoo.com/st?ad_type=iframe&ad_size=300x250&site=1580851&section_code=ADO3b
  • https://www.virustotal.com/de/url/639f767bb6de5e8b70499590e7c3a38ca047d1eb77b39e53b94b4aed4333148a/analysis/1396015602/
http://windowssoftwaire.eu5.org/PBDownForce.rar
  • https://www.virustotal.com/de/url/5fdf9ca80cddf232ad2ff32fe776e75eaa91283e858546e6902de39318734e59/analysis/1396014869/
MALWARE:
Packed.Win32.Black.d
  • https://www.virustotal.com/de/file/8f937adfb1ba4f2dcb2554a4a78d579438eec4351301141424f529ff1a17c0c3/analysis/1396014875/
ALSO:
http://windowssoftwaire.eu5.org/KeyText.rar
  • https://www.virustotal.com/de/url/b8dff45c4625e721c13fe7972f0c45ad5eebd3b0e4b7f634c98e155b87346242/analysis/1396016110/
Win32/Injector
  • https://www.virustotal.com/de/file/c5eb9f43af160569196b28476a3b89fcfde89dee6399c06e71766ff39a5763fb/analysis/1396016120/
IP:
5.9.106.214
  • https://www.virustotal.com/de/url/c675d95e168a09cbf8361aef286347b2473c933d8082578acee280d0607dd564/analysis/1396020096/
  • https://www.virustotal.com/de/ip-address/5.9.106.214/information/
BHA: 2.949
  • https://www.projecthoneypot.org/ip_5.9.106.214
HTML CODE CAN BE FOUND HERE:

Document hosting: UploadEdit.com

3/04/2014

BLOGGING MALWARE CONNECTION:
Yahoo Messenger ActiveX Control Command Execution
al-fatihahfatihah.hak.su (wen9.com, SOVIET UNION)


MALWARE NETWORK (MULTIPLE SITES): 
HIDDEN IFRAMES 
Yahoo Messenger ActiveX Control Command Execution

DOMAIN:
http://al-fatihah.hak.su/
  • https://www.virustotal.com/de/url/1962a67928d584eb43c11d5971d59699054493446146ea20cf2af8a62b63edc1/analysis/1393936132/
HTML:Iframe-inf
  • https://www.virustotal.com/de/file/be26f50ce7826afb4895abe505e156512d7c6f8f4b3ce2e02509e5a7a5548dbd/analysis/1393940987/
Yahoo Messenger ActiveX Control Command Execution
  • https://urlquery.net/report.php?id=9765152
  • https://urlquery.net/report.php?id=9765156
  • https://urlquery.net/report.php?id=9765157
http://al-fatihah.hak.su/index.html
  • https://www.virustotal.com/de/url/c55da57f592d7b30142708f1f0e35d03000a34c450229e8e72c51c27ecb8925e/analysis/1393947705/
HTML:Iframe-inf
  • https://www.virustotal.com/de/file/be26f50ce7826afb4895abe505e156512d7c6f8f4b3ce2e02509e5a7a5548dbd/analysis/1393940987/
Yahoo Messenger ActiveX Control Command Execution
  • https://urlquery.net/report.php?id=9766893

FULL REPORT:


Document hosting: UploadEdit.com

12/14/2013

Trojan.JS.Iframe.CIP & Hidden Iframe: onlygtamods.blogspot.co.at - (Austria)

GTA BLOG infected with Malware
MALICIOUS URL

onlygtamods.blogspot.co.at

  • https://www.virustotal.com/de/url/ad44797d2f7a3175fe0b9b8d6e6634a2d15b3338f4234b7c1fd06a4482d0cfbf/analysis/1387039150/
Infected With:

  • https://www.virustotal.com/de/file/7f1ff2384716f01014e269e7ba3dc3a7dc7cd0f280bea351e44b9cc7ca6c68d1/analysis/1387039360/
 --->  HIDDEN IFRAME TO:
 
DOMAIN: 

  • goo.gl
  • https://www.virustotal.com/de/url/21f8b60c2acbeb555e302df332fcccf6047eec8882ed892e0dacab9fe70c996a/analysis/
SPECIFIC LINK: 
  • goo.gl/xL64q
  • https://www.virustotal.com/de/url/e67569fade200ea3d83af40ce5051b2c27bf3e6d64b6c969fb93ebd1a64712ba/analysis/1387039842/ 
  • https://www.virustotal.com/de/file/518034ed78da007491b2854bfdc5385cfd197a6f81ef91a3ef1ac72ed85a1659/analysis/1387039364/
REF.:
http://jsunpack.jeek.org/?report=8527e7d771cc7a8dc7386a7b952b3e9b12c84dab