The URLs which were accessed during the exploit, most of these are harmless/known normal adware popups:- http://www.infinityads.com/popup.php? http://www.popuptraffic.com/assign.php? http://pagead2.googlesyndication.com/pagead/show_ads.js http://www.iseekstuff.com/lotr/lotr.htm http://u1.extreme-dm.com/i.gif http://pagead2.googlesyndication.com/pagead/ads? http://t0.extreme-dm.com/0.gif? http://pagead2.googlesyndication.com/pagead/ http://media.popuptraffic.com/scripts/popup.php? http://as.casalemedia.com/showad? http://adtrak.net/adjs.php? http://asg02.casalemedia.com/showad? http://adtrak.net/adlog.php? http://www1.multipops.com/loading.php? http://isg04.casalemedia.com/V2/37557/37557/index.html? http://ads.fortunecity.com/RealMedia/ads/adstream_sx.ads/stdinter/c3228d/121359@x31 http://www.iseekstuff.com/css/base.css http://isg04.casalemedia.com/V2/37557/37557/spyware2.gif http://66.70.21.80/scripts/click.php? http://pagead2.googlesyndication.com/pagead/ads? http://www.iseekstuff.com/fantasy/graphic/yellowtitle.gif http://www1.multipops.com/links.php? http://t1.extreme-dm.com/i.gif http://webpdp.gator.com/4/placement/256/ http://i.casalemedia.com/imp.gif? http://66.70.21.80/img/pixel.gif http://t0.extreme-dm.com/0.gif? http://65.17.207.40/framepb_1u.php http://asg02.casalemedia.com/imp.gif? http://asg02.casalemedia.com/pixy.gif http://np.default-homepage-network.com/np1/np1.htm http://np.default-homepage-network.com/np1//NP1.CHM http://np.default-homepage-network.com/np1//np1.exe http://207.44.156.26/~admin3/ron/ron.php? http:/// http://207.44.156.26/~admin3/ron/adsredir.php? http://207.44.156.26/~admin3/ron/adsredir.php? http://np.default-homepage-network.com/np2/np2.htm http://www.cheap-solutions.com/popup.html http://www.news-depot.com/ http://www.vivacorporation.com/VIVAMedicalTranscription.html http://www.deal-dudes.com/dp1.htm http://np.default-homepage-network.com/np2//NP2.CHM http://www.vivacorporation.com/viva.css http://www.cheap-solutions.com/themes/system/images/special.gif http://www.newsindex.com/images/line.jpg http://www.drgigabytes.com/images/dot.gif http://a408.g.akamai.net/f/408/1284/24h/image.netflix.com/NetFlix_Assets/affiliates/banners/a125125A.g http://www.qksz.net/1e-8f7j http://eoffersonline.com/banners/image.asp? http://cpaoffers.com/banner/1432/89&dp%3D0 http://www.news-depot.com//main.chm http://np.default-homepage-network.com/np2//np2.exe http://www.news-depot.com/msits.exe http://www.vivacorporation.com/images/clear.gif http://www.vivacorporation.com/images/viva_top_background.jpg http://67.15.4.62/traff.php http://67.15.4.62/traff.php http://np.default-homepage-network.com/np3/prenp3.htm? http://www.vivacorporation.com/images/viva_logo.gif http://np.default-homepage-network.com/np3/np3.htm http://np.default-homepage-network.com/np3//NP3.CHM http://np.default-homepage-network.com/np3//np3.exe http://www.media-ads.org/pops/Diet/600x400/600x400_11.gif http://www.qksrv.net/image-1239573-10289750 http://www.qksz.net/1e-8ctn http://www.qksrv.net/image-1239573-9955861 http://mirror.qkimg.net/0598/10289750-3 http://mirror.qkimg.net/0533/9955861-7 Below is the contents of the windows which were popped up (the html from the window which linked to the exploit is first):- -------------------- MAIN WINDOW ------------------- http://www.celebritysearchengine.co.uk/fantasy/e/ellemc.htm:-
|
Janet
Jackson |
Elle McPherson picture gallery |
|
A - B - C - D - E - F - G - H - I -K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
Paris Hilton - Britney Spears - Christina Aguilera - Jennifer Lopez - Orlando Bloom - Beyonce Knowles - Eminem - Hilary Duff - 50 Cent - Jessica Simpson - Courteny Cox - Linkin Park