Koobface Worm spreading trough Twitter
As you may have heard Twitter infected accounts are spreading the Koobface Worm:
Clicking on the link will send you to a page using a JavaScript redirection:
Below is the full code of this JavaScript file (wc2q57f.js). Check out the keywords it is using to find out where the user came from:
Finally, you get redirected to this page, with a fake flash player:
Now, out of curiosity, I tried to browse the malicious links using Mac OS X and Safari as my user-agent. Instead I get redirected to a site (private-teen-sex.com) promoting AdultFriendFinder:
Here are all the URLs that I could collect from infected Twitter profiles:
Warning, those sites are dangerous to visit!
oceanacompany.com/yourshow/
dramat.ilive.ro/extrimeclips/
hueythai.110mb.com/extrimefilms/
gandhiinternational.in/yourshow/
bit.ly/kFoP7
gandhiinternational.in/extrimetv/
64.37.106.170/mydemonstration/
reprographic.co.in/fantasticaction/
bit.ly/kFoP7
supportiesinergie.com/privateclips/
deathschildren.com/extrimeclips/
reprographic.co.in/megaperformans/
itprospecialists.com/cooldvd/
radiov.yoyo.pl/extrimedvd/
aspompierul.zzl.org/freeperformans/
siam9.com/coolclip/
lemujeme.cz/myshow/
www.caruso89.netsons.org/fantasticfilm/
hobbyboy.yoyo.pl/mydvd/
freecamz.fr.funpic.de/besttv/
yarentextil.com/publicclips/
64.37.106.170/myfilm/
reprographic.co.in/fantasticaction/
lepk.yoyo.pl/privatevids/
chaps.com.my/besttube/
supreeme.com/megademonstration/
chatlaklar.com/home.php
tinyurl.com/l48o9v
tinyurl.com/l4bslp
Jerome Segura
-
by
-
by
-
by
-
by
-
by
-
by
-
by
-
by
-
by
Comments:
|
|










