« What’s new?
Adult Site with wp gets hacked »

‘Welcome to Bulgaria’ site infected…

October 15th, 2009

Our HoneyPots caught this site as being malicious: legal.bg

bulgaria

They also gave us the drive-by download:

git77.biz/myy/dateoiou1.exe

But I wanted to know more on how this happened…

The Bulgarian site contains obfuscated Javascript:

javaobfuscated

And a particular long piece of unicode with a lot of ‘V’s in it:

gibber

the new variable uses the “split” function to clear the ‘V’s out of the way.

Another variable is setup as a string:

definevar

Then a ‘for loop’ function will go through each single character from the long variable without the ‘V’s:

for

Finally the document.write method will add the final piece to the puzzle, which is an iframe, but making sure it is obfuscated. The obfuscation part is defined in the long piece of unicode as “opacity=0″ (more on that later)

write1
write2

So, how did we deobfuscate this?

Well, we commented out the blue code above… and used our own document.write

sol

It basically takes the variable containing the iframe and writes it with a space between each character. That way, we can print it without it being hidden by the opacity argument. This is what it looks like, in clear text :-)

voli

So what about those iframes that are 0 in width and in height? Too easy to detect… Yes, probably. This one is “in your face” (width=”480″ height=”60″) and yet totally invisible.

The final payload is an executable detected on VirusTotal as:

http://www.virustotal.com/analisis/3b4f59eec0bc51dc40c787fef5e167c45f9d595e76712707f825cd66db845a15-1255539380

Thanks to Newaz Rafiq for his help on the deobfuscation part.

Jerome Segura

Malware ID: 4e1741d0a991ada20b9a788f2074f0ba.zip

Updated to add: This seems to be using the Fragus exploit kit. More info here from MalwareDomainList. (Thanks to MalwareScene)


    This entry was posted on Thursday, October 15th, 2009 at 10:55 am and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




ParetoLogic, a Microsoft Certified Partner

 

RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site
Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • URL Clearing House
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (4)
  • Botnets (3)
  • Conferences (4)
  • DDos (1)
  • Exploits (48)
  • Fake codecs (38)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (2)
  • Mac security (15)
  • Malware Trends (69)
  • Phishing (8)
  • Podcast (1)
  • ransomware (5)
  • Research (46)
  • Rogue software (53)
  • Rootkits (2)
  • scams (9)
  • Social Networking (6)
  • Uncategorized (118)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.