Posted 16 years ago
·
Author
I was using TOR to download from rapid, switched the ip and got connected to one of their ghost ips/servers 119.42.149.22 than a JavaScript snippet came from there [metasploit's exploit for MS06-014 injecting iframes]
the code tried to download (via XMLHttpRequest) the executable install.exe (which is a binnary virus
http://www.virustotal.com/analisis/f46f ... ac80c9e892
http://www.virustotal.com/analisis/4d8b ... a7c9e8e4b3)
It came from
http://golnanosat.com
The exe:
http://golnanosat.com/adw_files/5106/da ... l.exe?id=1 to add it to the startup programs, and to run it.
Fortunately for me i had IDM that picked up all the .exe's and didn't download them also i had to block the address with the range [ good old peerguardian with customized ip blocker list]
Is anyone using still TOR with IMVU?
Im switching to old ghostsurf.
the code tried to download (via XMLHttpRequest) the executable install.exe (which is a binnary virus
http://www.virustotal.com/analisis/f46f ... ac80c9e892
http://www.virustotal.com/analisis/4d8b ... a7c9e8e4b3)
It came from
http://golnanosat.com
The exe:
http://golnanosat.com/adw_files/5106/da ... l.exe?id=1 to add it to the startup programs, and to run it.
Fortunately for me i had IDM that picked up all the .exe's and didn't download them also i had to block the address with the range [ good old peerguardian with customized ip blocker list]
Is anyone using still TOR with IMVU?
Im switching to old ghostsurf.