Comedy site chucklemonkey.com is spreading malware through a malicious Java applet:
A code snippet is inserted in the main page (see above).
The Java applet comes from chucklemonkey.com/Slide.jar
It contains a malicious piece of code as shown below:
Upon successful infection, the malware calls fontom.no-ip.biz:1986/1234567890.functions
A server located in Morocco (41.142.111.146):
The comedy site has not been updated with fresh content for quite some time. More than likely the same can be said for security patches.
Jerome Segura
Leave a reply