this injected script also has several associated domains
- dd45h.8866.org/fkzd/16.htm
- wm.1kfie.cn/x150/xx.html
One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [VT Analysis]
this injected script also has several associated domains
One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [VT Analysis]
active sql-injection attack.
Injected scripts and exploits iframe to several urls such as:
the scripts generate some form of ‘time-based’ parameters that probably is only available for a brief period.
The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt
another round of sql-injection attacks.
x.js calls iframe src www.jejsaj.com/ya/index.html
jejsaj contains various exploits targeting among others
the exploits download trojans from www.wowand.com
another round of sql-injection attempt
Update: beware of this malicious script as it is making use of OWC 0-day.
Ref – http://isc.sans.org/diary.html?storyid=6811
a recent round of sql-injected link.
Read more »
This sql-injected script src has been around for some time.
The interesting point of this script is that it behaves differently if the injected site is from “.gov.cn” or “.edu.cn”. Code as shown below: Read more »
following previous post, a new injected script has emerged that resolves to same IP.
v.js retrieves another iframe src www.vieio.cn/i.htm.
This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js
This sql-injected script calls iframe www.gomne.cn/yh.htm
this is a new script that are being sql-injected.
z.js contains a iframe from www.893500.cn/2/index.htm
this sql-injected URL contains iframes to www.advpoints.com.
Seems to be profiting thru referrals rather than injecting malware.