Sucuri Research Labs

Sucuri on Twitter Sucuri on Facebook

Welcome to Sucuri's Research site Home  |  Notes  |  Malware data  |  Signatures  |  Tools  |  About

Sucuri Lab's is the home of our research and CIRT team, where we share some of the security issues and web-based malware that we are seeing in the "wild". Our goal to help educate our users and share information with the security community. For you have any questions, please email labs@sucuri.net.

We are also on Twitter at @sucurilabs.

If you are new here, you can check some of our resources:

Research Notes Malware data About

Latest note: Yahoo Leak You can check if your email is part of the yahoo leak here: http://labs.sucuri.net/?yahooleak. Thanks!     (by   Daniel B. Cid   | more notes )

Latest malware entries

Hidden iframes

Latest hidden iframes our scanner have identified on compromised web sites.

# of sites infectedTypeMalware / Domains
63iframehttps://tr.im/5UJJa
44iframehttp://motorisierung.kentuckydetoxcenters.com/boards/index.php?PHPSESSID=917v
15iframehttp://zugr.ru/player?playlistId=1800
10iframehttp://advertshot.ru/kod.php?param=5a5768496746313530302f39763039397861476c63685448676451657a55...
10iframehttp://123.forpost.compress.to/cf0/
9iframehttp://zkrnzil.hopto.org/wordpress/?bf7N
9iframehttp://kzgpzyf.ddnsking.com/wordpress/?bf7N
7iframehttp://afdbcvnxo.hopto.org/wordpress/?bf7N
4iframehttp://massatapahtumana.dchewitt.com/boards/index.php?PHPSESSID=9359f
3iframehttp://ypfpherxy.hopto.org/wordpress/?bf7N
3iframehttp://stjohnsdryden.org/img/common/download.php
2iframehttp://www.bilder-wiederherstellen.de/assets/sd.php
2iframehttp://artritismoafkooksel.chrisaperry.com/civis/search.php?keywords=46
1iframehttp://zzgbhscnit.hopto.org/wordpress/?bf7N
1iframehttp://news.gnezdo.ru/show/9662/block.html
Limited view... Only the top entries being displayed.

Conditional redirections

Conditional redirections we have detected (based on user agents or referers).

# of sites infectedTypeMalware / Domains
14redirectionshttp://cloud-security.ru
10redirectionshttp://tds.another-xxx-clips.biz/go.php?sid=1
6redirectionshttp://picstraffic.com/tds/in.cgi?20
5redirectionshttp://registers-24.ru/mishor?7
4redirectionshttp://mts8924.ru/an1/index.php
2redirectionshttp://yotraff.com/in.cgi?27/
2redirectionshttp://portalmobi.com/in.cgi?2
2redirectionshttp://kophon.wha.la/out.php?sid=1
2redirectionshttp://evoadspots2.com/in.cgi?15
1redirectionshttp://www.christianlouboutinonline.com/
1redirectionshttp://q9Szz.ddlsys.7710.info/?sov=1114390399
1redirectionshttp://operaminiupdates.info/tds/go.php?sid=1
1redirectionshttp://nationalsecuritydirect.com/hitin.php?land=20
1redirectionshttp://lily666.com/idfqp9.html
1redirectionshttp://LCOzz.ddlsys.7710.info/?sov=1114545710
Limited view... Only the top entries being displayed.

Spammers

Latest spammers we have detected sending comment, forum or SEO spam.

# of sites infectedTypeMalware / Domains
20+spammerhttp://123livesex.com/,forumspam,2014-01
20+spammerhttp://20min.ch,forumspam,2014-01
20+spammerhttp://90210daily.com/,forumspam,2014-01
20+spammerhttp://EzAdBlaster.com,forumspam,2014-01
20+spammerhttp://absolutefringe.com,forumspam,2014-01
20+spammerhttp://adaptfunrun.org/,forumspam,2014-01
20+spammerhttp://andresmarcossanchez.com/MichaelKors/ ,forumspam,2014-01
20+spammerhttp://appliancelandinc.com/,forumspam,2014-01
20+spammerhttp://audiobookkeeper.ru/,forumspam,2014-01
20+spammerhttp://australiainternetsearch.com/,forumspam,2014-01
20+spammerhttp://autism.sedl.org/index.php/about-us,forumspam,2014-01
20+spammerhttp://axanaxplease.com/,forumspam,2014-01
20+spammerhttp://ayurvedatradicional.com/wordpress/ ,forumspam,2014-01
20+spammerhttp://azezhomeloans.com/body.html,forumspam,2014-01
20+spammerhttp://baltimorecomiccon.com/sponsors/,forumspam,2014-01
20+spammerhttp://bashkiaprrenjas.com/,forumspam,2014-01
20+spammerhttp://bellezzaamica.it/Moncler-Sale-With-Free-Shipping.html,forumspam,2014-01
20+spammerhttp://birdsofstkittsnevis.com/files/,forumspam,2014-01
20+spammerhttp://bmaphoenix.org/young-professionals/,forumspam,2014-01
20+spammerhttp://bradblaze.com.au/,forumspam,2014-01
Limited view... Only the top entries being displayed.

Encoded javascript

Encoded javascript (redirecting to blackhole and other exploit kits) or to build a remote call.

# of sites infectedTypeMalware / Domains
266javascripthttp://mobi-auto.ru/m/"
17javascripthttp://mynewads.tk/1/": function mwkendyibszgwu(search,replace,subject){if(!(replace instanceof...
12javascripthttp://jqueryapi.info/?getsrc=ok: var IO1='KkSKpcCfngCdpxGcz5yJmVmc8VGdpJ3d8VWbh50ZhRVeCNHduVWb...
3javascripthttp://suptullog.com/": eval(String.fromCharCode(102,117,110,99,116,105,111,110,32,100,57,56,10...
205javascript<script type="text/javascript" src="http://g00.co/BtFVPd"></script>
105javascript<script type='text/javascript' src="http://gccanada.com/jquery.js"></script>
55javascript<script type="text/javascript" src="http://hodaproductphoto.co.uk/zp23mncc.php?id=62071516"></s...
49javascript<script language="JavaScript" src="http://www.hdsconsultores.net/kvxp.js"></script>
46javascript<script type='text/javascript' src='http://online-sale24.com/1.js'></script>
25javascript<script src="http://www.sadecereklam.net/script.php?ID=222"></script>
25javascript<script language="javascript" charset="UTF-8" type="text/javascript" src="http://hi.svk100hp.ru...
24javascript<script type='text/javascript' src='http://old.fapp.in/l.php'></script>
21javascript<script type="text/javascript" src="http://foto-nadio.hr/wp-content/themes/twentythirteen/2gp8l...
20javascript<script type="text/javascript" src="http://northcountryvets.com/wp-content/themes/genesis/ynf2q...
19javascript<script type="text/javascript" src="http://receptimira.ru/wp-content/themes/default/927mmlwt.ph...
15javascript<script type='text/javascript' src='http://tech9638514.ru/code/show.php?id=1904'></script>
13javascript<script type="text/javascript" src="http://estudioflordelotus.com.br/site/wp-content/themes/sal...
12javascript<script type="text/javascript" src="http://jpalegal.com/wp-includes/DCaXssbW.php?id=56049"></sc...
12javascript<script type="text/javascript" src="http://clubberz.com.au/pro___/wp-content/themes/rttheme17/c...
12javascript<script type="text/javascript" src="http://85.14.28.164/d/template/default-1.0.6/js/ie9.js"></s...
Limited view... Only the top entries being displayed.