One of the server called http:// fvgit.cn/01/index.htm hosting malicious code.
http:// fvgit.cn/01/index.htm
http:// fvgit.cn/01/real10.htm
http:// fvgit.cn/01/real11.htm
http:// fvgit.cn/01/fl.htm
http:// fvgit.cn/01/cx.htm
http:// fvgit.cn/01/06014.htm
-http://www. iegif.com/01/DUMete.exe
http:// fvgit.cn/01/I7.htm
http:// fvgit.cn/01/Ix7.htm (IE 7 0Day)
http:// fvgit.cn/01/ff.htm
-http://www. iegif.com/01/DUMete.exe
http:// fvgit.cn/01/xl.htm
However, the website not alive anymore when I write this article. This website consists from different webpages and link to it showed as above. At here I would like to emphasis at MS08-078.
The exploit inject malicious code to memory and initiate downloading trojan file to machine.

To decode the unicode, you may use FreShow or Malzilla tool.
The virustotal result for the DUMete.exe can be viewed
http://www.virustotal.com/analisis/399358e5ba2ff6973bc3a23e7eca8469
When further analysis to this link through IP address, there have similar website host at same IP address and offering same exploit.
http:// bfemf.cn/39/index.htm
http:// bfemf.cn/39/real10.htm
http:// bfemf.cn/39/real11.htm
http:// bfemf.cn/39/fl.htm
http:// bfemf.cn/39/cx.htm
http:// bfemf.cn/39/06014.htm
http:// bfemf.cn/39/I7.htm
http:// bfemf.cn/39/ff.htm
http:// bfemf.cn/39/xl.htm
Anyway, to preven this, antivirus companies and browser vendors already mark these website as malicious site to visit. :D
Merry Christmas !!
1 comments:
Type of bugs that can damage and ruin my computer.
If you are like me and tired many different scans in the past looking for something that will protect and clean your computer, give Search-and-destroy Antispyware a try. I found that the antispyware solution from Search-and-destroy (http://www.Search-and-destroy.com) is an excellent choice. It’s less expensive than many of the other scans I’ve tired but it finds the same type of bugs that can damage and ruin my computer. I am so happy with this scanner that I want to tell everyone about it so you can give it a try to. I’m sure you will love it.
Post a Comment