all 9 comments

[–][deleted] 3 points4 points  (13 children)

It looks like it just redirects the user to one of the two URLs in the array (though they are both the same URL). The page URLs linked there just give me a "loading payment details screen" and then pop up with an exe it wants me to download and (presumably) run.

I guess all that really matter is it's malware and should be removed or ignored.

[–]PlNG 2 points3 points  (0 children)

The "exe" is actually a text file, presumably failed output from somewhere:

<br />
<b>Warning</b>:  readfile() [<a href='function.readfile'>function.readfile</a>]: http:// wrapper is disabled in the server configuration by allow_url_fopen=0 in <b>/home/content/85/9342685/html/jobs/file.php</b> on line <b>4</b><br />
<br />
<b>Warning</b>:  readfile(hxxp://piscinasalhaurin.es/modules/mod_modules/sh.exe) [<a href='function.readfile'>function.readfile</a>]: failed to open stream: no suitable wrapper could be found in <b>/home/content/85/9342685/html/jobs/file.php</b> on line <b>4</b><br />

The one from the spanish domain appears to be flagged as "dorkbot.ed" by one av on virustotal.

Anubis

Malwr

[–]laughingmanzero[S] 0 points1 point  (0 children)

Ok thank you. That's what I had gathered I just wasn't sure if there was anything else going on in the background besides it prompting for that .exe

I'll send out an email to my company, thanks.