Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Historic malware entries for 2012-08-04Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-19   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   2013-05-01   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
20iframehttp://flipsphere.ru/in.cgi?16
16iframehttp://bioperm12.org/20/go.php?sid=1
8iframehttp://katestat.info/in.cgi?9
7iframehttp://purplefrigate.ru/in.cgi?16
6iframehttp://brownform.ru/in.cgi?15
4iframehttp://hazelwave.ru/in.cgi?16
4iframehttp://fabujob.net/?click=BD6D2
3iframehttp://oxsanasiberians.com/downloads/stats.php
2iframehttp://www.back2gether.com/wp-jmt.php
2iframehttp://nightvee59.aa.am/chisto/dabstepinattack.php'
2iframehttp://fabujob.net/?click=BC5DA
1iframehttp://opracowaniagraficzne.pl/10474443.html
1iframehttp://lop3.info/mazontms/redirect.php'
1iframehttp://lcaqfjhd.gr8domain.biz/vd/43;3848d14634284fd9c6c8138b0ef84d12
1iframehttp://jugendcafe-zwiesel.de/96254443.html
1iframehttp://hfjvdgl.portrelay.com/vd/43;9a788f6e680da94815f885cd2df58423
1iframehttp://dallastx.pairserver.com/87344443.html
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
159redirectionshttp://fitnes-internet.ru/sorento?5
141redirectionshttp://internetfitnes.ru/sorento?5
125redirectionshttp://center-fitnes.ru/sorento?5
95redirectionshttp://fitnesinternet.ru/sorento?5
95redirectionshttp://fitnescentre.ru/sorento?5
62redirectionshttp://internet-fitnes.ru/sorento?5
58redirectionshttp://web-fitnes.ru/iskustve?5
57redirectionshttp://fitnes-net.ru/iskustve?5
50redirectionshttp://centerfitnes.ru/sorento?5
40redirectionshttp://fitnes-internet.ru/sorento?5
33redirectionshttp://internetfitnes.ru/sorento?5
30redirectionshttp://magazinfitnes.ru/sorento?5
30redirectionshttp://center-fitnes.ru/sorento?5
27redirectionshttp://fitnes-global.ru/sorento?5
27redirectionshttp://fitnescentre.ru/sorento?5
26redirectionshttp://magazin-fitnes.ru/sorento?5
24redirectionshttp://2013-verygoods.ru/in.cgi?11
24redirectionshttp://2013supas.ru/joomlastar?4
23redirectionshttp://fitnesinternet.ru/sorento?5
21redirectionshttp://fitnes-corp.ru/shurimuri?5
13redirectionshttp://internet-fitnes.ru/sorento?5
12redirectionshttp://web-fitnes.ru/iskustve?5
12redirectionshttp://fitnes-net.ru/iskustve?5
11redirectionshttp://centerfitnes.ru/sorento?5
10redirectionshttp://msqlawkwardness.org.in/?5
10redirectionshttp://michaelmazur.net/xml.php
10redirectionshttp://mer-sat.ru/flayer?12
10redirectionshttp://fvzex80.info/in.cgi?7
10redirectionshttp://fitnesmagazine.ru/viola?5
9redirectionshttp://daliachuqimaysa.ru/gluce/index.php
6redirectionshttp://magazinfitnes.ru/sorento?5
6redirectionshttp://fitnes-corp.ru/shurimuri?5
6redirectionshttp://brendarco.ru/original/index.php
6redirectionshttp://24-verygoods.ru/in.cgi?9
5redirectionshttp://nash-fitnes.ru/nonalco?5
5redirectionshttp://miamiheattickets.com/http.php
5redirectionshttp://magazin-fitnes.ru/sorento?5
5redirectionshttp://live-fitnes.ru/shurimuri?5
5redirectionshttp://kogirlsnotcryz.ru:8080/forum/showthread.php?page=beb2436a164c6222
5redirectionshttp://info-fitnes.ru/interactive?5
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
1094javascript<script type="text/javascript" src="http://www.jquerys.org/ajax/libs/jquery/jquery-1.6.3.min.js...
74javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="143..120..1122..1404..1210..1188..1276.....
57javascript<scriptlanguage=JavaScript>document.write(<iframesrc=http://frankwscrises.in/showads.php?2&seor...
57javascript<script language='JavaScript'>document.write("<"+"if"+"ra"+"me"+" src='http://"+"frankwsc"+"ris...
42javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="156..130..1200..1443..1188..1521..1308.....
25javascript<script src="http://eighbo02rsbarr.rr.nu/sl.php"></script>
23javascript<script type='text/javascript'>var wow="frb2b2b3ddb1cob1b3tb1pn";c1="lonly"; if(-1==document.co...
16javascript<script type="text/javascript">if (typeof(redef_colors)=="undefined") { var div_colors = new ...
16javascript<script src="http://andsto57cksstar.rr.nu/sl.php"></script>
12javascript<script src=http://achtbanen.org/images/b-one-default.php ></script>
11javascript<script type="text/javascript" src="http://andws.com.br/ti/Check.php"></script>
10javascript<script>var url="http://onmouseup.info/stats.php";if((navigator.userAgent.toLowerCase().indexOf...
10javascript<script src="http://tartis78tscolla.rr.nu/sl.php"></script>
10javascript<script src="http://onlyforstatic.mine.nu/rss.js"></script>
9javascript<script src="http://brown74emphas.rr.nu/sl.php"></script>
9javascript<script language='JavaScript' type='text/javascript'>var postRmbn_width = "700px"; var postRmbn...
8javascript<script language="JavaScript">eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt...
7javascript<script src="http://xinthesidersdown.com/sl.php"></script>
6javascript<script src="http://tartis78tscolla.rr.nu/sl.php?v=1"></script>
5javascript<script type="text/javascript" src="http://aeg.com.br/us/Check.php"></script>
5javascript<script>try{1-prototype;}catch(bsdtwbd){q=412;} if(1){f=[1,0,95,94,23,30,92,102,89,109,100,91,1...
5javascript<script>try{1-prototype;}catch(bsdtwbd){q=412;} if(1){f=[1,0,95,94,23,30,92,102,89,109,100,91,1...
4javascript<script>try{1-prototype;}catch(bsdtwbd){q=412;} if(020==0x10){f=[1,0,95,94,23,30,92,102,89,109,...
3javascript<script type="text/javascript">var vbsp='6CF4890F';eval(function(p,a,c,k,e,d){e=function(c){ret...
3javascript<script>s="";try{q=document.createElement("p");q.appendChild("123"+n);}catch(qw){h=-016/7;try{a...
3javascript<script src="http://brown74emphas.rr.nu/sl.php?v=1"></script>
2javascript<script type="text/javascript">var vbsp='24D47C6B';eval(function(p,a,c,k,e,d){e=function(c){ret...
2javascript<script type="text/javascript" src="http://eumemo.com.br/010706.php"></script>
2javascript<script>try{n-=eval("p"+"rototype");}catch(zxc){e=eval;n="117..100..918..1170..990..990..1044.....
2javascript<script src="http://andsto57cksstar.rr.nu/sl.php?v=1"></script>
1javascript<script type="text/javascript">var vbsp='C0D06A5D';eval(function(p,a,c,k,e,d){e=function(c){ret...
Limited view (40 rows)... Only the top entries being displayed.