PandaLabs Blog : MS06-044 in the wild
A few days ago some small e-Commerce sites were compromised and were being used to distribute payloads for a Microsoft vulnerability, MS06-044
Ajaxで使われるXMLHttpRequestをつかってファイルをダウンロードしちゃうそうです。へぇー考えるなぁ。(q2l.exe wwwwww)
That payload uses the XMLHttpRequest (used in AJAX applications) to download in the background two files: q2l.exe and q1.dll from http://***.cc/q/ to the Windows Temp directory: C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp (this directory is obtained from the Windows environment variable TEMP).