Home > ParetoLogic Blogs > Malware Diaries > Iframes, PDF exploits and RBN
Reply
 
Thread Tools Display Modes
  #1  
Old 03-18-2009, 11:22 PM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Iframes, PDF exploits and RBN

*Our honeypot caught several legit sites that were infected and pushing*the same*drive-by download. I decided to take a closer look.

Upon visiting the site, a PDF file will open (and crash) trying to run an executable exploiting an Acrobat Reader vulnerability.

costa11

*I dug into the source code of the infected page. Strangely the malicious (and obfuscated) javascript code appears twice. The first occurrence was being commented out (did the web admin try to fix it?) but the second one was still active and in clear text.

costa3

I took a closer look at the JavaScript... It's all gibberish, so you have to use tools to make it readable. I used the free program Malzilla which revealed the culprit:



costa2

An ugly Iframe!!!

I checked this IP address and it is listed as part of the RBN (Russian Business Network). If you visit that IP, you will see even more obfuscation:

malzilla1*

Anyway, the PDF exploit can be opened with Notepad to reveal the malicious Javascript code:*



costa4

Most AV vendors already detect it:

costa5*

Jerome
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use