mailing list archives
RE: http://molecularmultimedia.com/ an exploitdistribution point (update2)
From: "Aditya Deshmukh" <aditya.deshmukh () online gateway strangled net>
Date: Tue, 4 Oct 2005 22:04:30 +0530
I've had the site www.ok-ok.biz disabled by the ISP, at least
it will deny the
perps the ability to find out who has been compromised. The
site is obvioulsy just a front, will see what can be done about this.
The site was found after 2 different attempts here are more details
http://newvisioncc.org/photo/myphoto.jpg which is
<iframe src="http://traff.root-soft.com" width="0" height="0"></iframe>
---- end myphoto.jpg
And http://traff.root-soft.com is
And molecularmultimedia.com is the front end to something more sinister....
Also visiting molecularmultimedia.com with mozilla with the latest version of
With all the patches still caued the trojan to be executed - I found this from
Norton antivir logs ....
It's amazing looking at the page source, there are at least 4
components of the page.
And they are pretty good also - new 0day for mozilla also 1.7.12!
Will let you all know if I find anything!...
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- RE: http://molecularmultimedia.com/ an exploitdistribution point (update2) Aditya Deshmukh (Oct 04)