http://dol.{BLOCKED}1.us:8081/update/base64.js
Publish Date: 19 mai 2013
Date/heure du blocage de l'URL: vendredi 3 mai 2013 20:20:00 GMT-8
Évaluation: : Élevé
Domaine: : ns01.us
Catégorie: Disease Vector
Description:
JS_EXPLOIT.MEA loads this site where its component for decoding base64 can be found. This malicious script was inserted onto a legitimate website of the US Department of Labor and downloads a Poison Ivy backdoor.