Monday, August 3, 2009

BitDefender China Website host malicious script

According to Chinese Security Forum, BitDefender at China was compromised with drive-by malicious script to exploit website.

Reference: kafan.cn

Level 0> http://www.bit361.com/
Level 1>http://www.bit361.com/js/fw.js
Level 1>http://www.bit361.com/img/01.jpg
Level 1>http://www.bit361.com/img/02.jpg
Level 1>http://www.bit361.com/img/03.jpg
Level 1>http://www.bit361.com/img/04.jpg
Level 1> http://www.bit361.com/images/eight.jpg
Level 1>http://%77%2e%6a%73%67%75%61%6e%67%6a%69%2e%63%6e ->http://w.jsguangji.cn
Level 2>http://w.jsguangji.cn/03.htm
Level 3>http://js.tongji.linezing.com/1209024/tongji.js
Level 3>http://w.jsguangji.cn/click.js
Level 3>http://w.jsguangji.cn/dex.html
Level 3>http://w.jsguangji.cn/456.htm
Level 4>http://w.jsguangji.cn/11.jpg
Level 4>http://w.jsguangji.cn/10.jpg
Level 4>http://w.jsguangji.cn/9.jpg
Level 4>http://w.jsguangji.cn/8.jpg
Level 4>http://w.jsguangji.cn/7.jpg
Level 4>http://w.jsguangji.cn/6.jpg
Level 4>http://w.jsguangji.cn/5.jpg
Level 4>http://w.jsguangji.cn/4.jpg
Level 4>http://w.jsguangji.cn/3.jpg
Level 5>http://w.taogu.org.cn/a.exe
Level 4>http://w.jsguangji.cn/2.jpg
Level 4>http://w.jsguangji.cn/1.jpg


0 comments: