Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

New Obfuscated Scripts in the Wild: /*LGPL*/

Symantec Security Response
January 8th, 2010
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Evolution of Security, Malicious Code, Security, Security Response, Security Risks, Vulnerabilities & Exploits
Facebook Twitter

Last December we saw a couple of malicious JavaScript strings being pasted into Web sites on compromised servers. The beginning of the scripts look like one of the following:

  • <script>/*GNU GPL*/ try{window.onload = function(){var ~
  • <script>/*CODE1*/ try{window.onload = function(){var ~

We’ve now confirmed a new version. One of the sites we saw was originally compromised with the "/*GNU GPL*/" script and was recently updated with the "/*LGPL*/" script. A top portion of the obfuscated script looks something like this:

<script>/*LGPL*/ try{ window.onload = function(){var C1nse3sk8o41s = document.createElement('s&c^$#r))i($p@&t^&'.repl

Once deobfuscated, it leads to a URL that looks something like this:

[http://]free-fr.rapidshare.com.hotlinkimage-com.thechocolateweb.ru:8080/51job.com/[REMOVED]/redtube.com/gittigidiyor.com/google.com/

The use of well-known domains in the URL string is an attempt by the attackers to circumvent other protection mechanisms that may be in place. In the example above, the actual domain resolves to thechocolateweb.ru, not the various other domains that appear in the URL.

The payload hasn't changed much from last year's attacks. When one visits a compromised site, the malicious JavaScript loads more JavaScript that contains an iframe tag, which opens another page containing two links. One link goes to a PDF file, which is detected as Trojan.Pidief.H or Bloodhound.Exploit.288. The other is to a JAR (Java ARchive) file, which is detected as Downloader.

Those two files use the following vulnerabilities to infect the computer with malware:

  • Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities (BID 27641)
  • Adobe Reader and Acrobat 'newplayer()' JavaScript Method Remote Code Execution Vulnerability (BID 37331)
  • Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities  (BID 32608)

Unfortunately, the patch for BID 37331 won't be out until January 12th, so you may want to consider disabling JavaScript in Adobe Reader until it is released.

The final payload includes malware like Trojan.Bredolab, Downloader.Fostrem, and Trojan.Zbot, along with security risks such as PrivacyCenter and a number of other misleading applications that may be detected as Trojan.FakeAV. It's important to keep your definition files up-to-date as these files are frequently being updated.

We also released a generic detection called Trojan.Malscript.B to catch the new malicious JavaScript, as well as scripts with similar code. IPS protection is also in place that will block the malicious Java Archive file using the HTTP Fragus Toolkit Download Activity IPS signature.
--------------
Thanks to Kaoru Hayashi for providing his analysis.

+1 (1 vote)
  • Symantec Security Response's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • W32.Stuxnet Variants
    Liam O Murchu - July 29, 2010
  • Tracking Cookies
    Ben Nahorney - July 28, 2010
  • After Football, Scammers Pursue the Cricket World Cup
    Mathew Maniyara - July 28, 2010
  • Fraudsters Offering Free Mobile Phone Airtime
    Mathew Maniyara - July 28, 2010
  • W32.Changeup: Visual Basic Polymorphic Code Uncovered
    Takayoshi Nakayama - July 28, 2010

Blog Tags

10.x 11.x 2010 State of Enterprise Security Report 419 scam 9.x and Earlier Adobe Acrobat Adobe Flash Adobe Reader Advanced Persistent Threats Amazon Antivirus2010 Apple Backdoor.Tidserv Backdoor.Trojan Brazil Brightmail Gateway Brightmail IQ Clickjacking Cricket World Cup 2011 DNS poisoning Earth Day Email Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security FIFA Father's Day Gary Coleman General Symantec Google IPS ISTR XV IT Healthcare Landscape IT Risk Management Infostealer.Bancos Infostealer.Gampass Internet Security Threat Report Java Live PC Care Malicious Code Michael Jackson Microsoft Microsoft Patch Tuesday Misleading Applications Mobile & Wireless Mobile Security Mother's Day Online Fraud Orkut PDF PDF spam Password Management Restore SEO Poisoning Security Security Risks Security Trends 2010 Soccer Social networking South Africa Spam Survey Sykipot Symantec State of Spam & Phishing Report SymbOS.Exy Symbian Tmphider Tracking Cookie Trojan.Bredolab Trojan.Dropper Trojan.FakeAV Trojan.Loginck Trojan.Mebroot Trojan.Pidief Trojan.Pidief.I Trojan.Pidief.J Trojan.Twebot Trojan.Vundo Trojan.Zbot Trojan.Zlob Trojan.Zlob.P VirusDoctor Vulnerabilities & Exploits W32.Changeup W32.Downadup W32.Koobface W32.Qakbot W32.Sality W32.Stuxnet W32.Stuxnet!lnk W32.Temphid W32.Virut Windows World Cup 2010 World Expo 2010 Zeus directory harvest attack facebook fakeav phishing rogue antivirus rootkit scams social media twitter typosquatting volcano zero-day vulnerability
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com