• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

Malicious .biz site and browser vulnerabilities

Myantispyware team November 20, 2005    

A user visited a webpage and got redirected to hxxp://iframebiz.biz/dl/adv443.php (tt changed to xx to protect anyone from getting there…)

Among other things… the page was obfuscated and many malicious bits of software loaded through javascript…. such as hxxp://iframebiz.biz/dl/adv443/sploit.anr and hxxp://iframebiz.biz/dl/loadadv443.exe and hxxp://iframebiz.biz/dl/adv443.hta and some sort of loaderadv443.jar and… http://iframebiz.biz/dl/adv443/x.chm

It looks like a bunch of malicious software trying to exploit a variety of vulnerabilities (old and new). Apparently this isn’t a new way of getting these installed (they found 9 DNS names have been used in the last week) – traffsale.biz iframesite.biz iframetraff.biz toolbartraff.biz buytraff.biz iframecash.biz toolbarurl.biz iframebiz.biz and toolbarbiz.biz all have been used by an machine at 81.9.5.10

They’ve tried contacting the ISP and for fun infected a VMware virtual machine. More than 50 files were pulled down from all over.

Not that Firefox is invincible, but … most exploits in the wild affect unpatched Internet Explorer vulnerabilities which is why I usually recommend Firefox…

Exploits & Vulnerabilities

 Previous Post

Protecting kids from spyware, adware and malware

Next Post 

Windows XP SP1 and Windows 2000 DoS vulnerability

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

2 Comments

  1. Danger
    ― December 2, 2005 - 2:59 pm  Reply

    How are they being injected into website files?

  2. Administrator
    ― December 2, 2005 - 4:43 pm  Reply

    It`s simple, owner website insert code with exploit to a page.
    For example: < iframe src=/path/to/expoloit width=0 height=0 >< /iframe >

Leave a Reply Cancel reply

New Guides

Fitowex.com Promo Codes: A Crypto Scam
scam alert
Elandex.com Promo Code Scam: What You Should Know
scam alert
Betaluxia.com Promo Codes: A Crypto Scam
scam alert
Bailwex.com Scam Alert: Fake Promo Codes
scam alert
The Tunelax.com Scam: A Detailed Look at the Bitcoin Giveaway Fraud

Follow Us

Search

Useful Guides

Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
remove android virus
How to remove virus from Android phone
How to reset Internet Explorer settings to default
This setting is enforced by your administrator (Removal guide)

Recent Guides

Protecting kids from spyware, adware and malware
How to show hidden files in Windows
Lock down your browser
IE-SPYAD: Restricted Sites List for Internet Explorer
Here’s how to use the HOST file to block ads

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.