CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Some italian sites with obfuscate script
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
EdgarBangkok

Trooper
Trooper


Joined: Dec 28, 2007
Posts: 25
Location: Thailand

PostPosted: Sat Apr 26, 2008 5:11 am    Post subject: Some italian sites with obfuscate script
Reply with quote

I find with my tool Webscanner some italian sites with obfuscate javascript

The first javascript redirect over page with javascript also strong obfuscated.

vvv.deegees.it
vvv.graphixmania.it
vvv.sabrinasalerno.com
vvv.skuolasprint.it
vvv.custommania.com
vvv.giovaniudccasteltermini.com

More info over

http://edetools.blogspot.com/2008/04/utilizzo-di-webscanner-nella-ricerca-di.html

and also

http://edetools.blogspot.com/2008/04/sito-le-chicche-di-cala-con-javascript.html

I try to decode second script but i have problem with function callee to string.
If on have people know to decode is good

Edgar from Bangkok Very Happy

Back to top
View users profile Send private message Visit posters website
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Sat Apr 26, 2008 8:04 am    Post subject:
Reply with quote

eaofir.com is not loading, so can't test the callee code.

Back to top
View users profile Send private message
EdgarBangkok

Trooper
Trooper


Joined: Dec 28, 2007
Posts: 25
Location: Thailand

PostPosted: Sat Apr 26, 2008 9:41 am    Post subject: links
Reply with quote

the link at page with obfuscate java after the first decode is
eaoafir.com/ld/grb

and url when open page is


Code:
http://eaoafir.com/cgi-bin/index.cgi?grobin



whit java online

Edgar Very Happy


Mod edit: Disabled link

Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sat Apr 26, 2008 11:40 am    Post subject:
Reply with quote

I've added the javascript code to the malware listserv.

CastleCops Link/p1082766-MD5_6ac26877a2009c0e39bafe5d405bc7a9_scit_exe.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Sat Apr 26, 2008 7:08 pm    Post subject:
Reply with quote

wasn't able to decode any of this javascript.
guess i've just been lucky to be able to decode most of the stuff i've seen so far.

in the second set of javascript, i think it is IE-specific.

callee.tostring has a slightly different implementation in IE and mozilla, so you must use the correct javascript interpreter to decode.

for more info see:
http://malzilla.sf.net/
http://isc.sans.org/diary.html?storyid=3231
http://isc.sans.org/diary.html?storyid=3219
http://isc.sans.org/diary.html?storyid=1519
http://www.malwaredomainlist.com/forums/index.php?topic=218.msg2161#msg2161

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 63
Location: South Carolina, USA

PostPosted: Sat Apr 26, 2008 9:05 pm    Post subject:
Reply with quote

mr. edgar, you posted a hot link for a malicious webpage:

Code:
hxxp://eaoafir.com/cgi-bin/index.cgi?grobin

Back to top
View users profile Send private message
jpcv

Guest
IP: 189.140.*.*






PostPosted: Sat Apr 26, 2008 11:57 pm    Post subject:
Reply with quote

Two new with the same malware

Code:
hxxp://fbcmfir.com/cgi-bin/index.cgi?grobin

hxxp://fgv2fir.com/cgi-bin/index.cgi?grobin

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Apr 27, 2008 12:20 am    Post subject:
Reply with quote

Thanks for posting the links, I'll add the malware to the malware listserv.

When I visited the 2nd link I got a 500 error, when I went back to the 1st link I got the same error. I think my IP may be blocked.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Apr 27, 2008 12:38 am    Post subject:
Reply with quote

I opened the site again on a different IP and let it do it's thing.

3 files were downloaded, 2 had the same MD5 hash and ran. The 3rd file appears to be corrupt.

I'll add them to the malware listserv.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
EdgarBangkok

Trooper
Trooper


Joined: Dec 28, 2007
Posts: 25
Location: Thailand

PostPosted: Sun Apr 27, 2008 12:38 am    Post subject: Others links
Reply with quote

Founds others sites with same javascript obfuscated

vvv.fluidifikas.it
vvv.ristoreggio.it
vvv.jacopo81.it
vvv.sevenpress.com
vvv.fasterage.net


Is possible malware links serve MBR ROOTKIT

and more new links with obfuscated javascript over my blog page
Some use "callee to string function" and very hard to decode.

http://edetools.blogspot.com/2008/04/sarebbero-decine-i-siti-italiani.html

Edgar Very Happy

Back to top
View users profile Send private message Visit posters website
Mej1

Guest
IP: 24.181.*.*






PostPosted: Wed Apr 30, 2008 5:54 pm    Post subject:
Reply with quote

MasterBootRoot Shocked

Back to top
darkuser

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 9
Location: USA

PostPosted: Wed Apr 30, 2008 6:03 pm    Post subject:
Reply with quote

hnoafir.com
is also doing this
possibly infected pdf
and mbr rootkit

Back to top
View users profile Send private message
darkuser

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 9
Location: USA

PostPosted: Wed Apr 30, 2008 6:13 pm    Post subject:
Reply with quote

more info
translated to english

http://translate.google.com/translate?hl=en&sl=it&u=http://maipiugromozon.blogspot.com/&sa=X&oi=translate&resnum=5&ct=result&prev=/search%3Fq%3Dhnoafir.com%26hl%3Den

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Wed Apr 30, 2008 7:15 pm    Post subject:
Reply with quote

I've downloaded some samples from

Code:
hnoafir.com


which I'll have a look at.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Cretem0nster

MIRT Hunter


Joined: Jul 02, 2005
Posts: 121
Location: USA
MIRT

PostPosted: Thu May 01, 2008 4:50 am    Post subject:
Reply with quote

I guess by now you figured out there is only 2 samples and well,the site names...heh...just names,all architectures are identical to one another.

Mej1 uses a special force to sniff then associate and then crawls silently until exact matches are found,he is my best friend and never lets me down. Wink

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer