CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Caca college

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3983

Phishing Squad

PostPosted: Sun Apr 06, 2008 8:13 pm    Post subject: Caca college
Reply with quote

hxxp://collegeofcomplexpm.com/
calls Iframe from
hxxp://figace.info/spl1/index.php?'+Math.round(Math.random()*122202)+'533a8'
which servers up an obfuscated Adodb exploit I think


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3983

Phishing Squad

PostPosted: Sun Apr 06, 2008 9:09 pm    Post subject:
Reply with quote

Also hxxp://collegeofcomplexpm.com/index.php
(previous was index.html)
calls code from
hxxp://orentraff.cn/in.cgi?5


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sat Apr 12, 2008 2:24 pm    Post subject:
Reply with quote

The site hosting the malware appears to be down.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3983

Phishing Squad

PostPosted: Sun Apr 20, 2008 8:27 pm    Post subject:
Reply with quote

hxxp://collegeofcomplexpm.com/start.php
Still active.


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
solcroft

MIRT Hunter


Joined: Apr 01, 2007
Posts: 188

MIRT

PostPosted: Tue Apr 22, 2008 6:07 am    Post subject:
Reply with quote

downie wrote:
hxxp://collegeofcomplexpm.com/start.php
Still active.

Chock-full of Viagra ads, but I couldn't find any scripts/iframes on that page.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Tue Apr 22, 2008 9:32 am    Post subject:
Reply with quote

I've added the malware to the malware listserv.

CastleCops Link/p1081287-MD5_59f01076f638870d574e3c15eaa60d86.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3983

Phishing Squad

PostPosted: Wed Apr 23, 2008 4:38 pm    Post subject:
Reply with quote

start.php is gone, still malware in the homepage I reckon.


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer