Malaysia’s GSC website hacked with 2117966.net

GSC's website injected with malicious iframe

“Today as I surf to GSC.com.my - place where most Malaysians make their bookings for cinema tickets, AVG Security Toolbar alerted me of a JS/Downloader.Agent threat coming from 2117966.net!”

All Malaysian’s should take the necessary step not to visit this site at the moment until this problem is fix.

Update: GSC has removed the exploit. You can now surf GSC.com.my without any worries.

We have made a report on our blog not too long ago about 10,000 website injected with malicious iframe - this is the same threat that is affecting GSC’s website. This particular threat takes advantage of the vulnerability in Internet Explorer ActiveX and SANS Internet Storm Center said that as a result of this threat a password-stealer program will be installed on the infected machine.

AVG alert of 2117966.net

Further looking at GSC’s html source code, we found related code entries to load a javascript “fuckjp.js” from 2117966.net.

GSC Infected Source Code

Update: GSC has removed the exploit. You can now surf GSC.com.my without any worries.

How to protect from malicious iframe exploitation?

 Subscribe to RSS   Bookmark and Share

30 Responses to “Malaysia’s GSC website hacked with 2117966.net”


  1. 1 Throx

    Yeah, this is one nasty iFrame hack. My webhosting provider got whole server infected and causing big lost of customer.

  2. 2 Shafique

    Hye There! Thanks a lot for the alert. I already alert all my friend. Ermm.. myspace also have been attack with the same method. all using iframe.

  3. 3 Dr. Safemode

    Yea, GSC is a very popular website. Someone without a proper protection could get hurt. >.<

    I’m currently using AVG version 8.0 which has a security toolbar installed on my web browser. It is based on the LinkScanner technology which was recently acquired by AVG.

    Even though I have turn off the security toolbar plugin for Firefox because the plugin was not supported by Firefox 2.0.0.13, AVG managed to block the infected script with its Web Shield.

  4. 4 Dr. Safemode

    The exploit has been removed from GSC. Yay!

  5. 5 surfer

    good news that it has been removed. but damaged has been done. with the promotion of free tickets for gsc in alamanda, i bet many has visited the site and been infected. perhaps a method to check for infection & ways to remove it would be helpful.

  6. 6 BlogMalaysia.com

    How to know if a computer is infected or not?

  7. 7 Dr. Safemode

    Because not all anti-virus is gonna be able to detect it.

    I guess installing a firewall would help personal data from being stolen.

    Firewall could track suspicious programs trying to send data over to the net.

  8. 8 winter@mmu

    Thx Mr.SafeMode for alerting us :P Juz drop by after seeing ur post appear in Lowyat.net .
    Huhuhu, anything harm coming soon, pls do alert me ^^

  9. 9 Dr. Safemode

    To check for suspicious files installed in your system in the last 30 days, you can use Deckard System Scanner(dss) which is downloadable at

    http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=19

  10. 10 emmiscient

    thank god, i’m using a more secured operating system .. =D

  11. 11 godfry

    Success didn’t spoil me, I’ve always been insufferable.

  12. 12 buy diggs

    Digg can send a lot of traffic to a site but if you’re not one of the eliete users on digg it can be hard to promote your content there. Some people make up for the innate unfairness on digg that gives established users prefrence over new users by buying diggs. This can be a good way to get some momentum behind your link so that the ‘bandwagon effect’ will kick in and other people will start digging you because they see you getting so many votes. The problem is this can be expensive as a lot of sites charge a dollar or more per vote but you can get them for much less at Basicdig.net. This makes Basicdig.net an ideal tool for people who are promoting content on digg for the first time or even the veteran promoter who is just tired of paying high prices.

  13. 13 website promotion software?

    web site marketing and advertising is without question practically all about the range of other internet pages linking to your site. without those backlinks you’re up the creek without a paddle. this became apparent to me shortly after becoming a member of what is actually in my opinion the best semi-automatic website link building tools on the web … promoting website

  14. 14 Marcel Delana

    I always enjoy reading quality articles by an individual who is obviously knowledgeable on their chosen subject. I’ll be following this thread with much interest. Keep up the good work, I will be back

  15. 15 Adam Polland

    I would suggest you research what software your going to use then come back and post your requirements again before buying hosting. cPanel is extremely easy to use and most web hosts use it as standard, we weary of any host offering ‘Unlimited Disk Space’ and always read Terms and Conditions before signing up. Again HostGator is widely regarded as being the best for Support, Ease of Use and Uptime. - I don’t work for HostGator just in case your wondering!

  16. 16 backlink seo

    I feel a lot more persons require to read this, very beneficial info.

  17. 17 Andre Parisien

    So is HGH oral the best? Or is there a advice to follow?

  18. 18 Freeda Klaameyer

    very nice post dude! great website… will be back soon!

  19. 19 Brian Frank

    Loved your article, keep writing

  20. 20 ongun akay

    shares use a fantastic web-site decent Gives thank you for the working hard to guide people

  21. 21 Pandora Ramiez

    liked this writing!

  22. 22 Lovie Ellwein

    So something sent out as host.rchost1234.com, and there is no A record. I surmise you can change the mail address, and since you got the bounce, you must have a way of receiving rchost1234.com email? So either add the A record in DNS or change the email to the working email address.

  23. 23 Stephan Beherns

    Almost everyone that makesmoney on the internet (even the millionaires) do so through affiliate marketing. Being successful in affiliate marketing involves knowing the formula that makes other affiliate marketers successful. For example, autoblogging. Autoblogging is one of the least well-known forms of making money online for quite some time… particularly because it’s quite difficult to make a good auto-blog. Yet, when done right, it can provide you with a constant passive income with the only real work required being the setting up process. Video Marketing, and several other marketing strategies are all designed to drive traffic to your site, can be incorporated gradually in order to raise the position your site appears in the SERPs when any one searches for a term related to your site. And yet, even this can be totally automated.

  24. 24 Ashley Faiola

    Just how many hours do you waste on the blog from day to day?

  25. 25 Cassi Tormey

    Where is the subscribe button, can’t find it anywhere and I want to subscribe.

  1. 1 - Different
  2. 2 Blog of Kepongboy » Blog Archive » GSC Website Get Hacked
  3. 3 GSC website hacked « leejeok
  4. 4 GSC website compromised « ~* ße HÆpy Æ|way§ *~
  5. 5 i’m saimatkong » GSC Website Hacked?

Leave a Reply