« HoneyPot Workflow
Chica del mes malware »

Sea, Hex and Sun

July 30th, 2009

In this post I’m going to show you some tricks used by malware authors to evade detection. We shall see redirections, obfuscated javascripts and rootkit.

First things first, here is a site that has been compromised (chinaforge.cn). The last line of code from the source page shows a “script”.

cn1

The URL is of course obfuscated. It is a redirect to a malicious site: w.siyou.org.cn

That page has rather interesting code starting with an if statement.

if (document.location.href.indexOf(”gov”)>=0) {} else payload

In other words, the script detects where the user is coming from, and if the string ‘gov’ is found it will do nothing. (Government sites?)

cn2

If the payload gets the green light, we get an iframe to the following domain: w.jsguangji.cn

cn3

That page contains yet again 2 iframes as well as javascript code:

cn4

Let’s take a turn and follow the first iframe:

cn5

Alright. We are going to stop here for a moment and see what this is all about.

What appears to be links to pictures is actually pieces of code (javascript). Here is the code revealed from one of the ‘picture’:

code

I downloaded all the ‘pictures’ and compiled the code together. Here is what it looks like:

cn7

More obfuscated javascript!

This time we may actually have reached our final destination:

cn8

Yes, all of that for a single file.

For the end user, however, things are a lot more simple. You browse to a compromised site, get redirected once, twice and then: wham! bam! a drive-by download as shown below:

cn10

Upon execution a file is created: c:\windows\tasks\conime.exe

To make things more difficult, the file is hidden:

cn11

But just to prove it is there, I rebooted under Ubuntu (dual boot) to show you:

ub

The file is detected by about half the AV vendors on VirusTotal:

cn13

Programs / OS  used for this post:

Malzilla
FileAlyzer
Ubuntu

If you want to do more research, I have uploaded the ‘pictures’ and the malware sample to our FTP.

Malware ID: jscode.zip

Malware ID: 3b10f98238023336aa753f9e072fb244.zip

Jerome Segura

    This entry was posted on Thursday, July 30th, 2009 at 4:14 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.