Help - Search - Members - Calendar
Full Version: hxxp://eng2007.741.com [In list]
Get Paid Forum - Get Paid Discussion > Get Paid To Programs > Sites Allegedly with problems of hacking/virus/0-iframes, autosearches etc ... > Personal pages with 0iframes or other nasty codes
JACKIE1944
I got a virus alert as well as all the other rubbish on this one hxxp://eng2007.741.com
wagdoll
Good find, I did a search online for one of the codes and it looks like a trojan installer, then ran it through Jutaky's detektor and thought I'd broken it, it took so long to return the results!! It's no wonder when you see the actuall readout...the megalocost thing is what came up as being the trojan installer, this is bad enough but then you have iframe money which has the .wmf exploit with more trojans. Then there are some other nasty 0 iframe programs and a bunch of search things in there. This is really, really appalling and yet because of them coming through "affiliate" programs you wouldn't have caught them from the source code without a lot of digging.#

This link is referring to the network that runs megalocost installs

http://research.sunbelt-software.com/threa...?threatid=15001

This guy has a bunch of PTR programs listed on this page with the same refid as on the iframemoney, so I really hope he doesn't try to send this at them...

CODE
Total zeroiframes found: 23
[quote=IframeChecker]
[B][COLOR=red]Zeroiframes detected: 23[/COLOR][/B]
Check took 249.05 seconds

[I](Level: 0) Url checked:[/I]
http://eng2007.741.com/
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 1) Url checked:[/I] [I](iframe source)[/I]
http://www.iframemoney.org/banner.php?id=thomaslts
Zeroiframes detected on this site: [B]2[/B]
No ad codes identified

[I](Level: 2) Url checked:[/I] [I](iframe source)[/I]
http://dgfjhewfndsbfsdvf.biz/adv/new.php?adv=4
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 2) Url checked:[/I] [I](iframe source)[/I]
http://www.iframemoney.org/milkus.html
Zeroiframes detected on this site: [B]7[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.webmasterlose.de/lose/clickbanner.php?id=9900&bid=39672&aid=39530
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.webmasterlose.de/lose/clickbanner.php?id=9900&bid=41580&aid=39530
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.webmasterlose.de/lose/clickbanner.php?id=9900&bid=39921&aid=39530
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.osptp.org/ptp.php?usr=milkus
[B]PTP URL within iframe![/B] (most PTPs consider this cheating)
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.auto-surf.net/betteln.php?user=kamilek&ref=kamilek
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](script source)[/I]
http://www.auto-surf.net/inc/overlib.js
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://paidcash.info/banery.html
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](script source)[/I]
http://www.lose-ads.de/lose/viewtext.php?id=2159&bid=6489&aid=5079
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](script source)[/I]
http://www.lose-ads.de/lose/viewtext.php?id=2159&bid=7257&aid=5079
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](script source)[/I]
http://www.lose-ads.de/lose/viewtext.php?id=2159&bid=6926&aid=5079
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://neoffic.com/t/?id=milkus
Zeroiframes detected on this site: [B]2[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](iframe source)[/I]
http://adod.info/tem/adcpm1.html
Zeroiframes detected on this site: [B]2[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://adod.info/hitadall.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://adod.info/hitadsong.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](script source)[/I]
http://count24.51yes.com/click.aspx?id=244842743&logo=1
Zeroiframes detected on this site: [B]1[/B]
No ad codes identified

[I](Level: 6) Url checked:[/I] [I](iframe source)[/I]
http://count24.51yes.com/sa.aspx?id=+countid+yesdata+
Blank page / could not connect

[I](Level: 4) Url checked:[/I] [I](iframe source)[/I]
http://www.pinghu.info/james/dollarad.html
Zeroiframes detected on this site: [B]7[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://deftseek.com/hitadabc.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seeksort.com/hitadabc.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seekaim.com/hitadabc.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seekgaze.com/hitadabc.php
Blank page / could not connect

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seekforyou.net/hitadabc.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seekstep.com/hitadfiq.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](iframe source)[/I]
http://seekforyou.net/hitadmax.php
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 5) Url checked:[/I] [I](script source)[/I]
type=text/javascript http://www.axill.com/ads/cpmh.js
Blank page / could not connect

[I](Level: 5) Url checked:[/I] [I](script source)[/I]
http://count10.51yes.com/click.aspx?id=108863220&logo=12
Zeroiframes detected on this site: [B]1[/B]
No ad codes identified

[I](Level: 6) Url checked:[/I] [I](iframe source)[/I]
http://count10.51yes.com/sa.aspx?id=+countid+yesdata+
Blank page / could not connect

[I](Level: 2) Url checked:[/I] [I](iframe source)[/I]
http://www.iframemoney.org/kamilet.html
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://dxptp.com/ptp.php?usr=kamilet
[B]PTP URL within iframe![/B] (most PTPs consider this cheating)
Zeroiframes detected on this site: [B]1[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](iframe source)[/I]
http://dxptp.com/adcbk.php?usr=kamilet&ip=213.216.199.10&id=1165845870
Blank page / could not connect

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.123-ptp.com/ptp.php?usr=kamilet
[B]PTP URL within iframe![/B] (most PTPs consider this cheating)
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 4) Url checked:[/I] [I](frame source)[/I]
scripts/include/ptp_top.php?usr=kamilet&credit=0&url=http://123-ptp.com/ad/ad123.html
Blank page / could not connect

[I](Level: 4) Url checked:[/I] [I](frame source)[/I]
http://123-ptp.com/ad/ad123.html
Blank page / could not connect

[I](Level: 3) Url checked:[/I] [I](iframe source)[/I]
http://www.osptp.org/ptp.php?usr=kamilet
[B]PTP URL within iframe![/B] (most PTPs consider this cheating)
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://banner.0catch.com/cgi-bin/popup_mainsite.js
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 2) Url checked:[/I] [I](iframe source)[/I]
http://banner.0catch.com/cgi-bin/+popurl+
Blank page / could not connect

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://jupiter.bravenet.com/rover/f?cid=zerocatch&ctype=3
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://ads.eccentrix.com/banners/angelcities_pop_under.js
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://www.v-links.net/adrotator.asp?wtype=1&id=1141
Blank page / could not connect

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://www.ranks.tw/cgi-bin/ad.js?id=thomas
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[I](Level: 2) Url checked:[/I] [I](script source)[/I]
http://64.27.0.235/cgi-bin/adp.js?id=thomas
Blank page / could not connect

[I](Level: 1) Url checked:[/I] [I](script source)[/I]
http://www.centurys.com.tw/web/alliances.asp?id=14320
Zeroiframes detected on this site: [B]0[/B]
No ad codes identified

[/quote]
Source code of submitted URL:

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; >
<title>My World</title>
<bgsound src="midi/complicated.mid" tppabs="midi/complicated.mid" loop="-1">
<STYLE type="text/css">
<!--
BODY{
  background-image : url("http://home.kimo.com.tw/thomaslts/img/bluebg.jpg");
  background-repeat: no-repeat;
  background-attachment: fixed;}
-->
<script>
cookie_name="pop1";
cook_value="1!!1165842200";
cook_expires="Mon, 11 Dec 2006 13:04:20 GMT";
document.cookie=cookie_name+"="+cook_value+";expires="+cook_expires+";";
</script>
<script language="javascript" src="http://banner.0catch.com/cgi-bin/popup_mainsite.js"></script>
<script src="http://jupiter.bravenet.com/rover/f?cid=zerocatch&ctype=3"></script>
<!-- Megalocast code begin -->
<!-- script language=javascript src="http://js.megalocast.net/installp.php?aff=13864"> -->
<!-- Megalocast code end -->
<wagdoll snipped here>
<body><p align="center"><br><iframe src="http://www.iframemoney.org/banner.php?id=thomaslts" width="460" height="60" border="0" frameborder="0" scrolling="no"></iframe>
cubster
Thanks Jackie and Wagdoll. I got one alert but probably would not have kept digging. Great job
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.