drive-by download

ansar313

New Member
Thread author
May 20, 2013
14
hi
there are some malware URLs in BLADE evalution lab that were detected as drive-by download attack.
how can i find what file is downloaded when the user go to these URLs?
for example anyone can say me what file downloaded through these URLs(notice:URLs are dangerous):
--------------------------------------------
hxxp://out.outdoorkitchendistributors.com/in.cgi?2
-----------------------
hxxp://deletefail.ru/
-------------------------
hxxp://85.234.190.13/tds/in.cgi?default
----------------------------
if these URL is not valid there are more URLs in BLADE evalution lab with this url:
http://www.blade-defender.org/eval-lab/
please help meeeeeeeeeeeeeeeee :huh:
 

Ink

Administrator
Verified
Jan 8, 2011
22,489
"for example anyone can say me what file downloaded through these URLs"

These URL lists are very old, circa 2010. Malicious URL or not, a legitimate website can be hosting exploits if hacked through specially crafted webpages.

> User opens webpage
> Webpage script detects vulnerable browser (or plugin)
> Exploit code is executed to deliver the malicious load
> User either runs the download, or it takes advantage of the vulnerability to execute(?)
> User infected without their knowledge.

PS: Correct me if I'm wrong.
 

Gnosis

Level 5
Apr 26, 2011
2,779
I assume that this is where "HTTPS Everywhere", and "NoScript" add-ons come in handy. Either that or keeping all your Adobe junk and Java updated punctually.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
One sign to determine, the drive by downloads is when browser hangs or crashed.

Its a sign of imjection of processes and files through selected location including temporary foldet.
 

DrBeenGolfing

Level 1
Verified
Mar 16, 2013
582
If you are trying to discover the process which these drive-by's work, buy one on these hacker websites and disect it's code yourself. Not exactly what you mean here. I think Earth has it right, though.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top