« BBC’s ‘Click’ breaks the law or does it?
The Return of the Hijacked Desktop »

Iframes, PDF exploits and RBN

March 18th, 2009

 Our honeypot caught several legit sites that were infected and pushing the same drive-by download. I decided to take a closer look.

Upon visiting the site, a PDF file will open (and crash) trying to run an executable exploiting an Acrobat Reader vulnerability.

costa11

 I dug into the source code of the infected page. Strangely the malicious (and obfuscated) javascript code appears twice. The first occurrence was being commented out (did the web admin try to fix it?) but the second one was still active and in clear text.

costa3

I took a closer look at the JavaScript… It’s all gibberish, so you have to use tools to make it readable. I used the free program Malzilla which revealed the culprit:

costa2

An ugly Iframe!!!

I checked this IP address and it is listed as part of the RBN (Russian Business Network). If you visit that IP, you will see even more obfuscation:

malzilla1 

Anyway, the PDF exploit can be opened with Notepad to reveal the malicious Javascript code: 

costa4

Most AV vendors already detect it:

costa5 

Jerome

    This entry was posted on Wednesday, March 18th, 2009 at 2:22 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.