malwageddon

'Styxy' Cool EK pattern

Jul 9th, 2013
134
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.84 KB | None | 0 0
  1. http://comingsfillsdays.biz/white/vessel_reinforce.php - landing page with PluginDetect (chuncked)
  2. HTTP/1.1 200 OK
  3. Server: nginx/1.0.15
  4. Date: Mon, 08 Jul 2013 15:21:47
  5. Content-Type: text/html
  6. Transfer-Encoding: chunked
  7. Connection: keep-alive
  8. X-Powered-By: PHP/5.3.23
  9.  
  10. http://comingsfillsdays.biz/white/than_printer_partial_mighty.html - 2nd 'chuncked' html with a parameter in <textarea>
  11. HTTP/1.1 200 OK
  12. Server: nginx/1.0.15
  13. Date: Mon, 08 Jul 2013 15:21:48
  14. Content-Type: text/html
  15. Transfer-Encoding: chunked
  16. Connection: keep-alive
  17. X-Powered-By: PHP/5.3.23
  18.  
  19. http://comingsfillsdays.biz/white/artificial_oral_jump_liberation.html - 3rd 'chuncked' html with a parameter in <textarea>
  20. HTTP/1.1 200 OK
  21. Server: nginx/1.0.15
  22. Date: Mon, 08 Jul 2013 15:21:49
  23. Content-Type: text/html
  24. Transfer-Encoding: chunked
  25. Connection: keep-alive
  26. X-Powered-By: PHP/5.3.23
  27.  
  28. http://comingsfillsdays.biz/white/resume_gay_outset.html - 4th 'chuncked' html with a function
  29. HTTP/1.1 200 OK
  30. Server: nginx/1.0.15
  31. Date: Mon, 08 Jul 2013 15:21:51
  32. Content-Type: text/html
  33. Transfer-Encoding: chunked
  34. Connection: keep-alive
  35. X-Powered-By: PHP/5.3.23
  36.  
  37. http://comingsfillsdays.biz/white/legally_deplore_fog_along.html - 5th 'chuncked' html with GET for JAR
  38. HTTP/1.1 200 OK
  39. Server: nginx/1.0.15
  40. Date: Mon, 08 Jul 2013 15:22:03
  41. Content-Type: text/html
  42. Transfer-Encoding: chunked
  43. Connection: keep-alive
  44. X-Powered-By: PHP/5.3.23
  45.  
  46. http://comingsfillsdays.biz/white/sleep-preach-affection-railway.jar - malicious Java JAR file
  47. HTTP/1.1 200 OK
  48. Server: nginx/1.0.15
  49. Date: Mon, 08 Jul 2013 15:23:12
  50. Content-Type: application/java-archive
  51. Connection: keep-alive
  52. Content-Length: 9095
  53. X-Powered-By: PHP/5.3.23
  54. Last-Modified: Mon, 08 Jul 2013 15:25:41
  55. Accept-Ranges: bytes
  56.  
  57. http://comingsfillsdays.biz/white/aid_socially_particle_boyfriend.txt?e=18 - GET for Initial Payload
Advertisement
Add Comment
Please, Sign In to add comment