| View previous topic :: View next topic |
| Author |
Message |
EdgarBangkok
Trooper

 Joined: Dec 28, 2007 Posts: 25 Location: Thailand
|
|
| Back to top |
|
 |
brewt
SIRT Handler Premium Member
 Joined: May 29, 2007 Posts: 792 Location: USA
|
Posted: Sat Apr 26, 2008 8:04 am Post subject: |
|
|
eaofir.com is not loading, so can't test the callee code.
|
|
| Back to top |
|
 |
EdgarBangkok
Trooper

 Joined: Dec 28, 2007 Posts: 25 Location: Thailand
|
Posted: Sat Apr 26, 2008 9:41 am Post subject: links |
|
|
the link at page with obfuscate java after the first decode is
eaoafir.com/ld/grb
and url when open page is
| Code: | | http://eaoafir.com/cgi-bin/index.cgi?grobin |
whit java online
Edgar
Mod edit: Disabled link
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5879
|
|
| Back to top |
|
 |
brewt
SIRT Handler Premium Member
 Joined: May 29, 2007 Posts: 792 Location: USA
|
|
| Back to top |
|
 |
redwolfe_98
Corporal

 Joined: Dec 16, 2003 Posts: 63 Location: South Carolina, USA
|
Posted: Sat Apr 26, 2008 9:05 pm Post subject: |
|
|
mr. edgar, you posted a hot link for a malicious webpage:
| Code: | | hxxp://eaoafir.com/cgi-bin/index.cgi?grobin |
|
|
| Back to top |
|
 |
jpcv
Guest IP: 189.140.*.*
|
Posted: Sat Apr 26, 2008 11:57 pm Post subject: |
|
|
Two new with the same malware
| Code: | hxxp://fbcmfir.com/cgi-bin/index.cgi?grobin
hxxp://fgv2fir.com/cgi-bin/index.cgi?grobin |
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5879
|
Posted: Sun Apr 27, 2008 12:20 am Post subject: |
|
|
Thanks for posting the links, I'll add the malware to the malware listserv.
When I visited the 2nd link I got a 500 error, when I went back to the 1st link I got the same error. I think my IP may be blocked. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5879
|
Posted: Sun Apr 27, 2008 12:38 am Post subject: |
|
|
I opened the site again on a different IP and let it do it's thing.
3 files were downloaded, 2 had the same MD5 hash and ran. The 3rd file appears to be corrupt.
I'll add them to the malware listserv. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
EdgarBangkok
Trooper

 Joined: Dec 28, 2007 Posts: 25 Location: Thailand
|
Posted: Sun Apr 27, 2008 12:38 am Post subject: Others links |
|
|
Founds others sites with same javascript obfuscated
vvv.fluidifikas.it
vvv.ristoreggio.it
vvv.jacopo81.it
vvv.sevenpress.com
vvv.fasterage.net
Is possible malware links serve MBR ROOTKIT
and more new links with obfuscated javascript over my blog page
Some use "callee to string function" and very hard to decode.
http://edetools.blogspot.com/2008/04/sarebbero-decine-i-siti-italiani.html
Edgar 
|
|
| Back to top |
|
 |
Mej1
Guest IP: 24.181.*.*
|
Posted: Wed Apr 30, 2008 5:54 pm Post subject: |
|
|
MasterBootRoot 
|
|
| Back to top |
|
 |
darkuser
Cadet

 Joined: Apr 30, 2008 Posts: 9 Location: USA
|
Posted: Wed Apr 30, 2008 6:03 pm Post subject: |
|
|
hnoafir.com
is also doing this
possibly infected pdf
and mbr rootkit
|
|
| Back to top |
|
 |
darkuser
Cadet

 Joined: Apr 30, 2008 Posts: 9 Location: USA
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5879
|
|
| Back to top |
|
 |
Cretem0nster
MIRT Hunter
 Joined: Jul 02, 2005 Posts: 121 Location: USA
|
Posted: Thu May 01, 2008 4:50 am Post subject: |
|
|
I guess by now you figured out there is only 2 samples and well,the site names...heh...just names,all architectures are identical to one another.
Mej1 uses a special force to sniff then associate and then crawls silently until exact matches are found,he is my best friend and never lets me down. 
|
|
| Back to top |
|
 |
|
|