Home > ParetoLogic Blogs > Malware Diaries > Home mortgage site gets owned and pwned
Reply
 
Thread Tools Display Modes
  #1  
Old 10-21-2009, 02:52 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Home mortgage site gets owned and pwned

It's late at the office, but I'm still here finding some bad stuff. The wife is out for dinner with a friend, and I get bored at home.

Anyway, our HoneyPots just picked up this drive-by from homemortgagenetwork.com

This is what the site looked like before it was owned:

gage1

This is what it looks like now:

gage2

Yes, a lot of blank space too!

But the interesting part can be found in its source code (click to enlarge):

gage3

It pushes a PDF exploit and the final download comes from:

mefa.ws/1/cjms1.exe

The file is, shall we say, poorly detected right now:

gage4

Warning, these links are live and may infect your PC!

Jerome Segura

Malware ID: 048346308777edf94dd4788dac20be54.zip
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use