Hijacked web server used for drive-by malware installations. Deceptive web pages planted on hundreds of sites load a set of Java Scripts which in turn attempt to load a malicious webpage.
In this case it is located on tesan.com.tr
Gary Warner links this to the Zeus bot, which steals passwords, and was recently involved in the arrest of a group of Ukrainians whole stole over $70 million from US companies.
*****
See more of the description of this problem at
*****
*****
CVE-2010-1885]
'WAIT PLEASE
'Loading…'
An exploit to spread malware promotes a deceptive webpage on tesan.com.tr that uses JavaScript planted at these locations
hXXp://50.57.29.172/hVg3GFAo/js.js
hXXp://finantariauto.ro/5ZqETXNE/js.js
hXXp://ipecturkey.com/E2UNfoGY/js.js
hXXp://oompa.de/VTwQKwDD/js.js
The scripts attempt to load a malicious webpage from
hXXp://209.59.217.193/showthread.php?t=d7ad916d1c0396ff
that leads to malware at
hXXp://209.59.217.193/q.php?f=ba33
hXXp://209.59.217.193/content/Qai.jar
Útil
Verifique se você foi comprometidoConecte-se com o Google para escanear seu histórico de navegação.
Analisamos mais de 2 milhões de sites e contamos. O WOT é uma extensão leve projetada para ajudá-lo a navegar com rapidez e segurança. Ele limpará seu navegador, o acelerará e protegerá suas informações privadas.