Sucuri Labs Weekly Review – June 22nd – 2012

Have you checked out Sucuri Labs? We have been adding a daily feed of the top web-based malware
samples that we find every day, and the number of compromised sites as well.

We separate the data into three main categories:

  • Hidden iframes
  • Conditional redirections (genereally done via .htaccess)
  • Encoded javascript.

This helps us understand how sites are getting compromised and how it is being executed in the browser.

Here are a few samples of the daily feed:

As far the top offenders for this week, here you go:

  1. – .htaccess redirection that affected a couple hundred different web sites.
  2. – Malicious iframe that has been active for a few weeks. And we keep seeing it.
  3. – Malicious iframe to this domain pretending to be from Google. It is offline right now, but we keep finding sites compromised with it.
  4. .ru redirections – Those have been going for many months, but they are still live. Some of domains are listed here:
  5. Javascript injections from – We are seeing many sites with injections from (and similar domains). Mostly via an iframe hidden via encoded javascript.

For more details, just visit Sucuri Labs to see the dump for each day.

Read more: Sucuri Labs Weekly Review – June 22nd – 2012

Story added 23. June 2012, content source with full text you can find at link above.