Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Welcome to the labHome  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

The goal of the Sucuri Malware Lab is to share some of the latest malware we are seeing in the "wild" and to help educate our users and share information with the security community. For you have any questions, please email labs@sucuri.net.

We are also on Twitter at @sucurilabs.

If you are new here, you can check some of our resources:

Research Notes Malware data About

Latest note: Yahoo Leak You can check if your email is part of the yahoo leak here: http://labs.sucuri.net/?yahooleak. Thanks!     (by   Daniel B. Cid   | more notes )

Latest malware entries

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
18iframehttp://www.2nf.com.vn/templates/beez/images/jpg.php
11iframehttp://www.gtagaming.com//forums/images/lightbox/in.php
11iframehttp://dragovend.ru/outstanding.html?2
10iframehttp://4ucredit.ru/in.cgi?4
6iframehttp://lghwee.pcanywhere.net/geowgjwiehgwvbb.cfg?11
6iframehttp://games.webhost31.ru/adxcsub.php
5iframehttp://jtyopol.freewww.biz/nighttrend.cgi?8
5iframehttp://bing.jigsaw3org.us/?12
4iframehttp://cportmuse.ru/Bermuda?8
3iframehttp://vizus1.ru/qqcxtyc.php
3iframehttp://veva.com.ua/cwnqqvk.php
3iframehttp://immobiliareilsole.it/jdsbgpd.php
3iframehttp://eda21.ru/hholydo.php
3iframehttp://9857.aqq.ru/ufgsjox.php
3iframehttp://55555-4.ru/jnontvd.php
2iframehttp://www.diggsnet.com/vklctap.php
2iframehttp://www.arts2heal.gr/xvlnfov.php
2iframehttp://wordwestsides.ru/y434.lLljcl?default
2iframehttp://transatlas.com.ua/gjgggsv.php
2iframehttp://sysgaia.com/ydnsdun.php
Limited view... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
29redirectionshttp://solfedgio6.ru/simple/go.php?sid=38
16redirectionshttp://www.3dcgianimation.com/omzd.html?h=1883330
12redirectionshttp://speardiver.com/ocef.html?h=1494741
8redirectionshttp://eosusa.com/cewf.html?h=3312309
6redirectionshttp://1006jrfjhjr.dynamicdns.org.uk:85/SNrXO5eZUmezafp1VSscRaEmTDduhjoEBK5
5redirectionshttp://ypnofkiq.ru/count28.php
5redirectionshttp://pyatnickiy.ru/track.php
5redirectionshttp://positive-general.ru/example/status.php
5redirectionshttp://eastmead1.ipower.com/hamf.html?h=690835
5redirectionshttp://biskehud.ru/count5.php
4redirectionshttp://www.pinnaclecoin.com/hccd.html?h=378885
4redirectionshttp://tegxejiq.ru/count28.php
4redirectionshttp://podilovy-fond.eu/hccd.html?h=378885
4redirectionshttp://nashifitnes.ru/nonalco?5
4redirectionshttp://mampoks.ru/track.php
4redirectionshttp://interjeroidejos.com/aood.html?h=1413865
4redirectionshttp://hecodat.de/zwmd.html?h=1579506
4redirectionshttp://brg-catalogues.com/mzcf.html?h=3176257
4redirectionshttp://aiv-shop.de/zczf.html?h=583044
3redirectionshttp://www6.uiopqw.jkub.com/
Limited view... Only the top entries being displayed.

Spammers

Latest spammers we have detected sending comment, forum or SEO spam.

# of sites infectedTypeMalware / Domains
20+spammerhttp://buypropeciatop.soup.io,forumspam,2013-05
20+spammerhttp://buypropeciatop.soup.io/,forumspam,2013-05
20+spammerhttp://finproridecia.pen.io,forumspam,2013-05
20+spammerhttp://finproridecia.pen.io/,forumspam,2013-05
20+spammerhttp://powiekszaniepenisac.pl,forumspam,2013-05
20+spammerhttp://propeciasxl.pen.io,forumspam,2013-05
20+spammerhttp://propeciasxl.pen.io/,forumspam,2013-05
20+spammerhttp://www.2013jordantop.com/,forumspam,2013-05
20+spammerhttp://www.2013jordantop.com/index.php?route=product/category,forumspam,2013-05
20+spammerhttp://www.chloehanabi.com/,forumspam,2013-05
20+spammerhttp://www.chloematsuri.com/,forumspam,2013-05
20+spammerhttp://www.lovepaulsmith.japanbuy.jp/,forumspam,2013-05
20+spammerhttp://www.miumiucity.com,forumspam,2013-05
20+spammerhttp://www.miumiuroom.com/,forumspam,2013-05
20+spammerhttp://www.miumiuvivid.com/,forumspam,2013-05
20+spammerhttp://www.paulsmith.japanbuy.jp/,forumspam,2013-05
20+spammerhttp://www.paulsmithsummer.japanbuy.jp/,forumspam,2013-05
20+spammerhttp://www.restaurant-primavera.at/wp-content/upgrade/go/montblanc/,forumspam,2013-05
20+spammerhttp://www.restaurant-primavera.at/wp-content/upgrade/go/montblancde/,forumspam,2013-05
20+spammerhttp://www.stylessline.com,forumspam,2013-05
Limited view... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
10javascripthttp://americanmobile.ca/forum.php?tp=675eafec431b1f72": var t="";var arr="646f63756d656e742e77...
4javascripthttp://124.217.249.45/~user/html/TDS/go.php?sid=1: function v51865b5a5fbba(v51865b5a5fc6a){ fun...
2javascripthttp://zbestprice.org/tent/KcW8: function v4a2fb30324343(v4a2fb3032472a){ function v4a2fb30324b...
2javascripthttp://ynwqmwhnlw.organiccrap.com/d/404.php?go=1: s="";try{q=document.createElement("p");q.appe...
2javascripthttp://pokesack.ru:8080: var t="";var h="";var G;if(G!='m'){G=''};var D_="";function C() {var S...
1javascripthttp://securityandroidupdate.iway-services.com.ar/fix.php": var enkripsi="'1Aqapkrv'1G'2Ckd'0:l...
1javascripthttp://medicaidarmedicare.com: jsr1=[105,46,116,101,99,47,114,100,58,97,100,116,114,111,101,104...
1javascripthttp://bocpoo.com/?2289843": eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C...
1javascripthttp://biotechpharmhealthcare.com: jzs1=[99,104,97,98,112,104,104,116,47,97,99,116,114,116,105,...
267javascript<script type="text/javascript" src="http://sem-dv.ru/jquery-update.php"></script>
134javascript<script type="text/javascript" language="javascript" > function zzzfff() { var ik = document.cr...
100javascript<script type="text/javascript" language="javascript" > function zzzfff() { var jtc = document.c...
53javascript<script src="http://changeip.changeip.name/rsize.js"></script>
39javascript<script type="text/javascript" src="http://sodiummetal.com/wp-content/plugins/wp_modx/jquery-1....
34javascript<script type="text/javascript" language="javascript" > function zzzfff() { var pr = document.cr...
26javascript<script type="text/javascript" src="http://sodiummetal.com/wp-content/plugins/wp_modx/jquery-1....
16javascript<script src="http://sweepstakesandcontestsnow.com/nl.php?nnn=1"></script>
11javascript<script type="text/javascript" src="http://abrahamspath.org.uk/cb.php">"POC"</script>
10javascript<script src=http://dibsalimentos.com.br/images/kphz/gifimgud.php ></script>
9javascript<script src=http://il-falco.de/__installation/indexc.php ></script>
Limited view... Only the top entries being displayed.