Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Latest Malware Entries (24 hrs)Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-22   |   2013-05-19   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
41iframehttp://www.scs.tv/wp-content/themes/twentyeleven/colors/update.php
40iframehttp://www.2nf.com.vn/templates/beez/images/jpg.php
18iframehttp://rozblog.com/ads/image.php?size_id=7
14iframehttp://swvgvgldodz.myfw.us/jquery/get.php?ver=jquery.latest.js
14iframehttp://karatepacan.co.cc/up/go.php?sid=2
10iframehttp://seusalum.ru/selection.html?2
10iframehttp://adsalemedia.ru/in.cgi?12
8iframehttp://reoenqybu.myfw.us/jquery/get.php?ver=jquery.latest.js
8iframehttp://ontspanningspraktijk-iguazu.nl/bhndpyc.php
8iframehttp://delectric.com.mx/aohkfdq.php
8iframehttp://am10.ru/m/mp3poisk.php
8iframehttp://178.77.77.80/psyohty.php
7iframehttp://www.constanta.ws/chat.html
7iframehttp://kontura.hr/pajelqy.php
7iframehttp://formularze.otwartaszkola.pl/emljfby.php
6iframehttp://rivamarsa.com/qnajwvw.php
6iframehttp://pakkhatpit.net/bwkyyur.php
6iframehttp://kerima-tools.de/rjpegeq.php
6iframehttp://expohleb.newhost.ru/snnubho.php
6iframehttp://danovabud.net/ylxdvll.php
6iframehttp://bairesline.com.ar/gsltuvs.php
5iframehttp://wintented.ru/backpackers.html?2
5iframehttp://prime-aerosols.com/eedutng.php
5iframehttp://herbmarket.co.uk/grbqnmk.php
5iframehttp://fmrepresentaciones.com/jxyibed.php
5iframehttp://connectconsulting.co/htiqqjk.php
5iframehttp://addon.alfapointer.us/?6
4iframehttp://www.grupporagni.it/dam/counter.php
4iframehttp://repairmyhome.ca/jfvhsmk.php
4iframehttp://puczynski.pl/tpdddwv.php
4iframehttp://przychodniarodzina.pl/myrvikp.php
4iframehttp://protocolmindm.com/img2/count.htm
4iframehttp://municipalite.denholm.qc.ca/poinaiw.php
4iframehttp://minsociety.org/usjacyi.php
4iframehttp://itfv.net/mxreerw.php
4iframehttp://familystori.com/ehmhmfb.php
4iframehttp://continent-mebel.ru/aadkqge.php
4iframehttp://btagent.ru/qlqifgt.php
4iframehttp://bamerica.us/cyeuxnn.php
4iframehttp://absenergia.pl/iyghpup.php
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
36redirectionshttp://solfedgio5.ru/moneysyst/get_link.php?platnik=minecraft
28redirectionshttp://nerto-skiper.ru/palerm?12
27redirectionshttp://flintstudio.com
20redirectionshttp://mampoks.ru/track.php
17redirectionshttp://solfedgio5.ru/simple/go.php?sid=38
12redirectionshttp://medicsec.ru/
12redirectionshttp://ajnyjcen.ru/count21.php
10redirectionshttp://crzyluxtds.in/go.php?sid=1
9redirectionshttp://qovizki.ru/count12.php
9redirectionshttp://kifedqih.ru/count21.php
8redirectionshttp://haqkimve.us/count21.php
6redirectionshttp://startpool.ru/exclusive/index.php
6redirectionshttp://poasm.qpoe.com/
6redirectionshttp://doormoney.biz/
6redirectionshttp://cefoai.com/aula/traf.php
5redirectionshttp://xudyhbes.ru/count6.php
5redirectionshttp://uvpk-audit.ru/cat/count.php
5redirectionshttp://sixcharactersuccessfully.ru/extended?7
5redirectionshttp://mampoks.ru/track.php
5redirectionshttp://fitnes-global.ru/sorento?5
5redirectionshttp://ceesolierook.nl/esd.php
4redirectionshttp://snmsc.org/ohcd.html?h=1254562
4redirectionshttp://selxaqop.us/count21.php
4redirectionshttp://qovizki.ru/count12.php
4redirectionshttp://kpero.ddns.me.uk/
3redirectionshttp://tcpostwald.fr/media/esd.php
3redirectionshttp://sommetslutfy.com/zbun.html?h=2811228
3redirectionshttp://ldnescort.biz/qb8zT7pw.php
3redirectionshttp://interstation.ca/wp-content/rel.php
3redirectionshttp://carbondreams.com/clk.php
3redirectionshttp://ajnyjcen.ru/count21.php
2redirectionshttp://webllink.com/go.php?sid=14
2redirectionshttp://uploads-xxx.ru/?8
2redirectionshttp://startpool.ru/exclusive/index.php
2redirectionshttp://redboneskingston.com/hlfy.html?h=2594463
2redirectionshttp://realtrafffistock.ru/rpop.php?fl=4do3e8
2redirectionshttp://progressionhospital.ru/massmedia?8
2redirectionshttp://pillsm.com/v2/
2redirectionshttp://pagesinxt.com/?dn=batraherbals.com
2redirectionshttp://necktiesscaling.ru/VEREIN?8
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
16javascripthttp://pics.bubbled.cn/gallery/hardcore/?23c4f60c1b9f604d6ffb21cba59930: var syZzIc="P2zLa%";va...
9javascripthttp://www.prometei.in.ua/": document.write(unescape('%3c%73%74%79%6c%65%20%74%79%70%65%3d%22%7...
2javascripthttp://frazzo.com/test3.php\": jolc=new Array(39,44,32,54,46,38,45,55,109,52,49,42,55,38,107,97...
1javascripthttp://ywzjvqssv.myfw.us/t/vc.php?go=2: try{abre++}catch(a6ba34y){try{dsgsdh&2}catch(asab){e=wi...
33javascript<script src="http://pakesrry.info/rsize.js"></script>
21javascript<script src="http://popspace.virgilio.us/pop.php?id=1"></script>
13javascript<script src="http://newdomme.changeip.name/rsize.js"></script>
12javascript<script src="http://odnaknopka.ru/ok3.js" type="text/javascript"></script>
11javascript<script type="text/javascript" src="http://abrahamspath.org.uk/cb.php">"POC"</script>
9javascript<script type="text/javascript" language="javascript" > (function () { var id = '8'; var aihsq09...
2javascript<script src=http://salesio.net/images/ferris_wheel_spinning_md_wht.php ></script>
2javascript<script src="http://revise92dinjur.rr.nu/mm.php?d=x1"></script>
2javascript<script>document.write('<style>.vb_style_forum {filter: alpha(opacity=0);opacity: 0.0;width: 20...
1javascript<script type="text/javascript" src="http://argoauto.net/tmp/index-bkp.php"></script>
Limited view (40 rows)... Only the top entries being displayed.