LOD 0x03

Websites defaced by R3YR3 !!

http://www.paidantivirus.com         

http://www.viruseliminate.com       

Both websites are owned by same person ( has taken WHOIS privacy service).

R3YR3 is a member of Indonesian Defacers group .  It seems another member , Flyff666 from same group is resposible for Win32.Sality.aa virus as detected by Kaspersky and he  himself  has given different names like W32.Sarap.B or W32.Amburadul.Virus or has taken code from them. Infected files are here and I think this webserver itself is infected. ( Files are in double extensions , this virus is infecting Image file format like JPG,  gif, png etc.)

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: