Tag Archives: redkit

8×8 Script Leads to Infinity Drive-By

The “8×8” script I’m referring to includes a link that looks like this: hxxp://www.example .com/JB3xd6iX.php?id=87342871 And can be detected using a regular expression that looks something like this: /^.*\/[a-z0-9A-Z]{8}\.php\?id=\d{8}$ One set of links redirect users to social engineering scams (e.g. … Continue reading

Posted in Exploit Packs, Malscript | Tagged , , , , | Comments Off on 8×8 Script Leads to Infinity Drive-By

Exploit Delivery Networks

Exploit packs are normally set up on a hacker-controlled server. Compromised websites or malicious email links lead unsuspecting users to the drive-by landing page on the server. While this keeps the main control panel, renter’s panel, crypter, statistics, etc all … Continue reading

Posted in Exploit Packs | Tagged , , , , , | Comments Off on Exploit Delivery Networks

The Resurrection of RedKit

“RedKit” was once a thriving exploit pack then faded away leaving behind artifacts on several abandoned hosts which are still triggering broken redirection alerts to this day. Within the past couple of months, however, we are witnessing a deliberate return … Continue reading

Posted in Exploit Packs | Tagged , , , , | Comments Off on The Resurrection of RedKit