Translate

Posts mit dem Label Malicious Iframe werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Malicious Iframe werden angezeigt. Alle Posts anzeigen

2/19/2014

click.mail.buyagift.co.uk & Youtube Link
MALICIOUS VISITOR OF THE WEEK trying to Phish
Your Google Password through Youtube (United States)





MALICIOUS YOUTUBE REDIRECT: MALICIOUS IFRAME INJECTION

DOMAIN:
http://click.mail.buyagift.co.uk/
  • https://www.virustotal.com/de/url/5357cd79fa64155e0804990792b59aab3546cd94b23f5abd5313ccd7027fe734/analysis/1392761651/
MALICIOUS LINK:
http://click.mail.buyagift.co.uk/?qs=4c3712ac45056a7b6c1e1e482ce77aff893a18ed225bb5f3fdf56d31d4997264
  • https://www.virustotal.com/de/url/2369a8c9a7d199893f1d50aac025a9969129e0522084c62b47168695e34da79c/analysis/1392760542/
  • http://jsunpack.jeek.org/?report=3f91355b61b05c78dde2547cd2e9caac2588194f
MALICIOUS IFRAME INJECTION(s): (3 PATTERNS)
  • https://urlquery.net/report.php?id=9515948
  • https://urlquery.net/report.php?id=9515950
  • https://urlquery.net/report.php?id=9515955
FULL REPORT:

Document hosting: UploadEdit.com


2/14/2014

SINCE 2009: www.cafi.it
Infected with Malware: Malicious Iframe Injection
At the Moment: HEUR:Trojan.Script.Iframer (ITALY & UKRAINE)


MALICIOUS DOMAIN ALREADY SINCE 2009: HEUR:Trojan.Script.Iframer (RBN 422) (UKRAINE)
http://www.cafi.it/
  • https://www.virustotal.com/de/url/7bd6d2f5f61ade1dcfe6c3357fd48b812d1f40ef8d54b3feae0a71cb831dd2b1/analysis/1392383368/
INFECTION: 
HEUR:Trojan.Script.Iframer
  • https://www.virustotal.com/de/file/3510b819f8d1d209bb267f3a721f9cb040fc2c609412e7ace7f2dcd75528e67d/analysis/1392384000/
Mal/Iframe-F
  • https://www.virustotal.com/de/file/6eb573fba0944e608d57dc882860149f14bdb2368a295ac19e93f7e6a0072386/analysis/1392383703/
Malicious iframe injection
Javascript associated with malicious code
  • https://urlquery.net/report.php?id=9433018
--->
http://91.207.61.32/.r/.fi/index.php
  • https://www.virustotal.com/de/url/9d80e5be6628f7734d3fd816c391733b5c4e491c2f96818e22738b8a9c2ed5c7/analysis/1392384629/
  • https://urlquery.net/report.php?id=9433214

NEWLY DETECTED: www.albertomanganaro.it
Infected with HEUR:Trojan.Script.Generic
(ITALY)


NEWLY DETECTED MALWARE SITE FROM ITALY: HEUR:Trojan.Script.Generic

Malicious iframe injection
  • https://urlquery.net/report.php?id=9432480
http://www.albertomanganaro.it/
  • https://www.virustotal.com/de/url/48d1ce8ef5d827edda2d76a7f190c37d64812b63c905739df28a28101a4732fd/analysis/1392334229/
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/d246753919f66e3b34e54e24c34b4ec331e07afa0a695b4763c7637470a7dea6/analysis/1392335647/
The complete report can be found here:

Document hosting: UploadEdit.com


2/13/2014

ANGLER EXPLOIT KIT:
IP 37.9.53.204
Category MALICIOUS IP/DOMAIN
(UNITED KINGDOM & RUSSIAN FEDERATION)




The following DOMAIN / IP is compromised with the ANGLER EXPLOIT KIT which mainly is to use vulnerbilities in Microsoft SILVERLIGHT.

ORIGINS: UNITED KINGDOM & RUSSIAN FEDERATION

http://37.9.53.204/
  • https://www.virustotal.com/de/url/248fe87973d0950dbe2699af672f4cfa25b99d6642e33fa04e995af929d97cc0/analysis/1392317892/
SPECIFIC LINK:
http://37.9.53.204/mobile.php?niche=newcj
  • https://www.virustotal.com/de/url/fd0581fc5f7e6b847021e161e81a7b67edab23275cf66aa05055f983e3df4fee/analysis/1392317833/
Malware.HTML.Iframe (paranoid heuristics)
  • http://virusscan.jotti.org/de/scanresult/6f18ec5f9439692aa66e4b0a8b021a2ee1073e6a
  • https://www.virustotal.com/de/file/cfae597233232ae04ac8fdc4809a00159c720e657ca6c32a4c4d5e45bdba9568/analysis/1392319600/
SCRIPT(s) CAN BE FOUND HERE:
  • http://jsunpack.jeek.org/?report=4404603b06b5bc656d0d7364c99f9921ba109afc
0) Angler exploit kit URL pattern
1) Angler EK Landing Page
2) Possible AnglerEK Java Exploit/Payload Structure Jan 16 2014
3) suspicious - gzipped file via JAVA - could be pack200-ed JAR
4) Possible Secondary Indicator of Java Exploit (Artifact Observed mostly in EKs/a few mis-configured apps)
5) Angler EK encrypted binary (3) Jan 17 2013

  • https://urlquery.net/report.php?id=9424546
The complete analysis review with more details can be found here:
Document hosting: UploadEdit.com




2/10/2014

NEW:
yansalamandra.ru
HEUR:Trojan.Script.Generic
Russian Federation




NEWLY DETECTED: MALICIOUS IFRAME (RBN 365)
yansalamandra.ru
  • https://www.virustotal.com/de/url/67921025f91c62ba5e76eda2f819051ee0ad0d25d2aa551bdb8b7f215979ce12/analysis/1391972916/

INFECTION: 
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/4d878e5f2db1d468d80a1d15ab6a5bef205b4834e85e5226f8ba9cae406e4b64/analysis/1391974022/
  • https://urlquery.net/report.php?id=9327064
  • http://jsunpack.jeek.org/?report=5c2537adab93e2e9a6fa9108f149dc6d9138b788
--->
advomn.pp.ua
  • https://www.virustotal.com/de/url/93856bf13af0b2df401a4080f6b72274156db06cc73e05499e0d3cffe0cf7e86/analysis/1391975226/
  • https://urlquery.net/report.php?id=9327399
advomn.pp.ua/38c190227eaddbe1e920ad1a993701980a6d4d8e516d3011c2fc023a042b7d4b171a7f801a278e4630354f01a9232a6a3a2ec980002e92716c9ce0dc480c29447345c6dee2d30344b6b
  • https://www.virustotal.com/de/url/df4bd15c09f7e998375234b0ec08a26dce90f07c9cd2da9dde32f54ca1336bb2/analysis/1391975200/
--->
changeip.changeip.name/rsize.js
  • https://www.virustotal.com/de/url/41c106f4f24956e8e6d031bc20861b77b7b9674f8ad231ef4e51fff8892e90a3/analysis/1391974447/
  • https://urlquery.net/report.php?id=9327265
  • https://urlquery.net/report.php?id=9327273
------------------------------------------

OTHER MALICIOUS LINK:

yansalamandra.ru/administrator/help/en-GB/chinchin.js
  • https://www.virustotal.com/de/url/286c044eac09bac2fe39efa3e21ab1e60bbee92349e1499c02e7efe4e02d7eec/analysis/1391975320/

INFECTION:
Troj/JSRedir-MN
  • https://www.virustotal.com/de/file/c3755028d1adf4d41fd5d0ffd1bdabffc9a093be438025b491fca6901c74cc06/analysis/1391975322/
  • http://jsunpack.jeek.org/?report=009476f8e2cc5e8c96b8a51b339bcd41b26c9851

2/06/2014

aromavietnam.com
Malicious Domain Infected with:
HEUR:Trojan.Script.Generic & Trojan.JS.Iframe.aeq
(EXPLOIT from VIETNAM)


MALWARE: EXPLOIT


DOMAIN:
aromavietnam.com
  • https://www.virustotal.com/de/url/ec13cdcd880da204742fbbb17ebb754f78fa9e9916c5d900393e779c09d017bf/analysis/1391695139/

Infected with: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/000ab3f5794c646ded51dd9b66d10749834dce17193ee9da1c28520fd23c52c1/analysis/1391697040/

EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator
  • https://urlquery.net/report.php?id=9256862
  • https://urlquery.net/report.php?id=9258051
  • https://urlquery.net/report.php?id=9258064

--->
173.237.187.203/post.php?id=704732
  • https://www.virustotal.com/de/url/aa23c1e60447fa417c7bf7cd25fdf3257e0b354fb1a37a143b8334b7bd96c1f5/analysis/1391698495/
  • https://urlquery.net/report.php?id=9258108

OTHER MALICIOUS LINK(s):
aromavietnam.com/stmenu.js
  • https://www.virustotal.com/de/url/e30a7f2e0271567938041e58cbccb2b2273e217c83110083ec79c4b747bef41c/analysis/1391694780/

Infected with: Trojan.JS.Iframe.aeq
  • https://www.virustotal.com/de/file/864d33b798d3c718263cb7ed78bea4a007133af53c704f45a54f0ca5e832aaa0/analysis/1391695003/

--->
37.59.120.98/704732.js
  • https://www.virustotal.com/de/url/eef9a6a86ae865da21b27b35623e5756f3569ceacb11a0a0fc444de13c413c0c/analysis/1391696634/
REF.: http://jsunpack.jeek.org/?report=05a453d8b0c4094c355d0f93ec02fe7f9619f4a2