Attachments
pwd: xylibox
(561.53 KiB) Downloaded 64 times
(561.53 KiB) Downloaded 64 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:looks like they have new injected:Well, there also obfuscated iframe, but hxxp://solnechnozdes.ru/iframe.php?id=0xxnnc3e8793z0nevu1f4o36ncdvg34 is down for me.
script src=http://adorabletots.co.uk/tmp/js.php
found this in an shop im watching. at the beginning it was infected with the stuff we talked at the beginning, now it is this.
google search brings 370 results at this moment.
http://lamacom.net/images/j/
http://www.nordic-austria.at/shop/index.php
markusg wrote:what about this:obfuscated iframeCode: Select allhttp://lamacom.net/images/j/