Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Historic malware entries for 2012-07-24Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-19   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   2013-05-01   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
447iframehttp://bitcolony.ru/in.cgi?16
381iframehttp://pinkium.ru/in.cgi?16
174iframehttp://gigaflight.ru/in.cgi?16
156iframehttp://rec-creations.com/adv.php
118iframehttp://competechart.ru/in.cgi?16
35iframehttp://atomiality.ru/in.cgi?16
33iframehttp://niu-sae.com/stats.php
31iframehttp://whitecada.ru/in.cgi?16
24iframehttp://greencricket.ru/in.cgi?16
20iframehttp://usuarionovo.com/
20iframehttp://rolyjyl.ru/count30.php
19iframehttp://orangeroller.ru/in.cgi?16
17iframehttp://playart.org/sites/stats.php
16iframehttp://unlinedrj.org/news.php?id=e6f6402caf60df3a
16iframehttp://flipsphere.ru/in.cgi?16
14iframehttp://blogroute.ru/in.cgi?16
11iframehttp://smuss.net/redirect.php
10iframehttp://poseyhumane.org/stats.php
9iframehttp://slapfeatureladen.info/in.cgi?16
9iframehttp://searchcomforgotten.org/news.php?id=e6f6402caf60df3a
9iframehttp://scriptslimit.info/in.cgi?16
9iframehttp://resizingoriginals.net/main.php?page=2e714bd974e37854
8iframehttp://sluxxqqgykewolmoli.in/in.cgi?default
8iframehttp://orangemoth.ru/in.cgi?16
7iframehttp://somermerch.ru/in.cgi?16
5iframehttp://zumobtr.ru/gate.php?f=971749
5iframehttp://ineed.co.nz/adverts/media.php
4iframehttp://pairedpixels.com/vaca/stats.php
4iframehttp://creativeironart.net/images/stats.php
4iframehttp://clients.bluecava.com/data?p=D440F31E-EDE7-4BB2-B328-527A10AB7572
3iframehttp://orangecricket.ru/in.cgi?16
3iframehttp://methuenedge.com/stats.php
3iframehttp://makeupstyle.net/css-wvn.php
3iframehttp://arvaglobal.com/vwop.php
2iframehttp://uploadingbefuddling.org/in.cgi?16
2iframehttp://htpcapital.com/main.php?page=98d3bf6d08596d13
2iframehttp://blog.zzub.it/wp-ojb.php
1iframehttp://respondsourceeffects.info/in.cgi?16
1iframehttp://goldensmagnetic.com/in.cgi?16
1iframehttp://erapost.net/?click=15062171
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
160redirectionshttp://1-verygoods.ru/in.cgi?9
146redirectionshttp://verygood24.ru/in.cgi?9
92redirectionshttp://verygoods-24.ru/in.cgi?9
75redirectionshttp://verygood-24.ru/in.cgi?9
64redirectionshttp://bitcolony.ru/in.cgi?16
46redirectionshttp://bronzesage.ru/in.cgi?16
45redirectionshttp://som-oda.ru/in.cgi?4
43redirectionshttp://pdabattery.net/ads/counter.php
42redirectionshttp://verygoods24.ru/in.cgi?9
36redirectionshttp://pinkium.ru/in.cgi?16
32redirectionshttp://1verygoods.ru/in.cgi?9
28redirectionshttp://176.9.179.140/
26redirectionshttp://michaelmazur.net/xml.php
23redirectionshttp://miamiheattickets.com/http.php
22redirectionshttp://daliachuqimaysa.ru/gluce/index.php
18redirectionshttp://gigaflight.ru/in.cgi?16
17redirectionshttp://udzycaf.ru/count24.php
17redirectionshttp://poowabah.info/counter.php
17redirectionshttp://bitcolony.ru/in.cgi?16
13redirectionshttp://udzycaf.ru/count24.php
12redirectionshttp://pinkium.ru/in.cgi?16
12redirectionshttp://mercurytutors.com/stats.php
12redirectionshttp://intersccaned.ru/sytrim?3
12redirectionshttp://competechart.ru/in.cgi?16
11redirectionshttp://jeidokuyetrxxw.de.nr/12044425.html
10redirectionshttp://bronzesage.ru/in.cgi?16
9redirectionshttp://som-oda.ru/in.cgi?4
9redirectionshttp://on-mas.ru/acu?11
8redirectionshttp://porterco.net/counter.php
8redirectionshttp://lundf-creation.de/main.php
7redirectionshttp://service2010.ru/in.cgi?8
6redirectionshttp://www.online-open.com/
6redirectionshttp://udzycaf.ru/count24.php?option=com_content
6redirectionshttp://silveronly.ru/images/acdxe1.php
6redirectionshttp://pills.ind.in/in.cgi?4
6redirectionshttp://mytresca.com/counter.php
6redirectionshttp://heartofpole.net/xml.php
6redirectionshttp://gigaflight.ru/in.cgi?16
6redirectionshttp://2014inter.ru/in.cgi?12
5redirectionshttp://wtwqwtgaga.ru/qpgap?9
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
256javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="117..100..918..1170..990..990..1044..1...
156javascript<script type="text/javascript">document.write('<iframe src="http://rec-creations.com/adv.php" n...
45javascript<script>s="";try{q=document.createElement("p");a=(q)?"appendChild":12;q[a]("123"+n);}catch(qw){...
39javascript<script type="text/javascript" src="http://aeg.com.br/us/Check.php"></script>
33javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="117..100..900..1110..891..1170..981..1...
29javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="117..100..918..1170..990..990..1044..1...
26javascript<script>try{n-=eval("p"+"rototype");}catch(zxc){e=eval;n="81..90..945..1020..288..400..900..111...
23javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{prototype...
20javascript<script type="text/javascript">document.write('<iframe src="http://rolyjyl.ru/count30.php" name...
20javascript<script>i=0;try{prototype;}catch(z){h="harCode";f=['-33c-33c63c60c-10c-2c58c69c57c75c67c59c68c7...
20javascript<script>eval(String.fromCharCode(102,117,110,99,116,105,111,110,32,103,101,116,95,100,111,109,9...
18javascript<script type="text/javascript" language="javascript" src="http://earnforum.net//styles/DVGFX2/c...
18javascript<script type="text/javascript" language="javascript" src="http://baykalmotorshow.ru//admin/jque...
18javascript<script src="http://sweepstakesandcontestsnow.com/nl.php?nnn=1"></script>
16javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="81..90..945..1020..288..400..900..1110...
16javascript<script>try{12+prototype;}catch(zxc){e=window["eva"+"l"];n="81.90.945.1020.288.400.900.1110.891...
15javascript<script type="text/javascript" language="javascript" src="http://buitengewoon-oss.nl//_vti_log/...
15javascript<script src="http://naked-adsl.co.za.tempurlza.co.cc/wp-content/themes/twentyeleven/js/html5.js...
13javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="81..90..945..1020..288..400..900..1110...
13javascript<script>try{1-prototype;}catch(asd){x=2;} if(x){f=[0,-1,94,93,22,29,91,101,88,108,99,90,101,106...
12javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="81..90..945..1020..288..400..900..1110...
11javascript<script type="text/javascript" src="http://andws.com.br/ti/Check.php"></script>
11javascript<script language="Javascript" SRC="http://recreativ.ru/tizers.php?sid=779&bn=Y6cU2wvofd&cat=45"...
10javascript<script src="http://ort40ruck.rr.nu/pmg.php?d=x"></script>
10javascript<script src="http://origi75nalund.rr.nu/pmg.php?d=x"></script>
10javascript<script src=http://jorgealcidesbuffa.com/Resguardos/test.php ></script>
8javascript<script type="text/javascript" src="http://asjo.com.br/js/Check.php"></script>
8javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{bcsd=prot...
8javascript<script>try{n-=eval("p"+"rototype");}catch(zxc){e=eval;n="117..100..918..1170..990..990..1044.....
7javascript<script type="text/javascript" src="http://jsfeedget.com/js.php"></script>
7javascript<script type="text/javascript" src="http://gostats.ru/js/counter.js"></script>
7javascript<script type="text/javascript" language="javascript" src="/dd" ></script>
7javascript<script src="http://vepl26asmad.rr.nu/pmg.php?d=x"></script>
7javascript<script src="http://quitie30sbehavi.rr.nu/pmg.php?d=x"></script>
7javascript<script src="http://onsh13ipwo.rr.nu/pmg.php?d=x"></script>
7javascript<script src="http://dmin19istra.rr.nu/pmg.php?d=x"></script>
7javascript<script src="http://alsu33rpris.rr.nu/pmg.php?d=x"></script>
6javascript<script type="text/javascript">var vbsp='D4065D32';eval(function(p,a,c,k,e,d){e=function(c){ret...
6javascript<script>try{q=document.createElement("u");q.appendChild(q+"");}catch(qw){h=-012/5;zz='a'+'l';f=...
6javascript<script>try{eval("pro"+"totype")>0;}catch(zxc){e=eval;n="81..90..945..1020..288..400..900..1110...
Limited view (40 rows)... Only the top entries being displayed.