hxxp://ca.rewardzsonline.c0m/?sov=64372601&noaudio=1&nopop=1&noalert=1&ctrl1=nodl&id=XNSX.v4RHART3T5NS1A8809V0GF41L2#
All I have to say is, what a damn fail. If you’re looking to get $$$, at least make the download button work. Like really. Come on
hxxp://ca.rewardzsonline.c0m/?sov=64372601&noaudio=1&nopop=1&noalert=1&ctrl1=nodl&id=XNSX.v4RHART3T5NS1A8809V0GF41L2#
All I have to say is, what a damn fail. If you’re looking to get $$$, at least make the download button work. Like really. Come on
That IP history is not very rewarding as well: 208.87.35.103 → http://support.clean-mx.de/clean-mx/viruses.php?review=208.87.35.103&sort=first%20desc
and one IP number up they are spreading: ET TROJAN Kazy/Kryptor/Cycbot Trojan Checkin 2 K
Kazy/Kryptor/Cycbot how is that for a nice online reward? ;D
Stay away,
pol
Too late. Should probably check my computer. (Damn it, I left it on that website). Frick, Not to mention the school protection didn’t block it. Surprising. Time to email some people! I’ll report it to MDL?
Not only files should be run inside a VM Alan.
Or you could use Linux, but that is vulnerable to Java/Flash Malware cause there is
almost no actual Antivirus for Linux.
Besides an IE and Chrome friendly padding, did not see that much alarming here: http://jsunpack.jeek.org/?report=4982836dd480657b43680ef4ea572b15380cc1d4
As I said only a Google Browser Diff:
Not identical
Google: 9830 bytes Firefox: 9974 bytes
Diff: 144 bytes
First difference:
ect_download" id=“direct_download” style=“height: 0px; width: 0px; position: absolute; left: 0px; top: 0px;”> …
pol
What!?! I stumbled upon it by accident. I knew something was up… So I posted here. Thanks for the smart alec comment though. Quite enjoyable. I’m smart enough to know not to run malicious websites on my host computer…
If that means what I think it means. Does that mean Chrome is not able to have the malware be loaded? Or should I still get the logs going?
Also, I hate IE, and I saw that coding and though a 0px X 0px wouldn’t show anything. That mean it’s silent or no malware present?
What I have seen from MX Virus Watch recent malware has been closed, maybe you had a lucky escape. Anyway it looks like that,
pol