Author Topic: Need help with JS:Redirector-H [Trj]  (Read 12494 times)

0 Members and 1 Guest are viewing this topic.

darknight

  • Guest
Need help with JS:Redirector-H [Trj]
« on: December 08, 2011, 01:00:12 AM »
Hi,

When I visited my friends blog hxxp://www.baba3od.com Avast blocked me and showing the site is infected with the "JS:Redirector-MR [Trj]" Trojan:
 



So is the site really infected or a false positive? Any help would be greatly appreciated :)

Thanks

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Need help with JS:Redirector-H [Trj]
« Reply #1 on: December 08, 2011, 01:19:34 AM »
Sucuri says clean. I didn't find anything significant in the source code, but then again, I skimmed over it.

Quote from: Sucuri Sitecheck
Domain clean by Google Safe Browsing
Domain clean by Norton Safe Web
Domain clean on Phish tank
Domain clean on the Opera browser
Domain clean on Sucuri IP/URL malware blacklist

Possible false positive. Sirmer found the malicious coding. Tell your friend to get it removed.
« Last Edit: December 08, 2011, 11:58:21 PM by Donovansrb10 »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Need help with JS:Redirector-H [Trj]
« Reply #2 on: December 08, 2011, 01:09:36 PM »
Hello,
this detection is a correct

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37603
  • Not a avast user
Re: Need help with JS:Redirector-H [Trj]
« Reply #3 on: December 08, 2011, 01:53:12 PM »
Hello,
this detection is a correct
I am sure the OP would be interested in more details

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Need help with JS:Redirector-H [Trj]
« Reply #4 on: December 08, 2011, 02:40:23 PM »
Malicious part of code

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: Need help with JS:Redirector-H [Trj]
« Reply #5 on: December 08, 2011, 06:11:32 PM »
Isn't this a detection for the Dean Edwards embedded counter code javascript?
What does it do unobfuscated? See:
http://dean.edwards.name/packer/

pol
« Last Edit: December 08, 2011, 06:41:03 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Need help with JS:Redirector-H [Trj]
« Reply #6 on: December 08, 2011, 11:16:23 PM »
Yes, this is detection for the Dean Edwards embedded counter code javascript.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: Need help with JS:Redirector-H [Trj]
« Reply #7 on: December 08, 2011, 11:29:52 PM »
@Sirmer,
Thank you for the feedback for all of us, and the heads-up for webmasters/developers out there.
Hack alert (Armorize) had the warning out for this since 09-2011.
Very good it is being detected. It is a mass WordPress infection going on,
read from Dean Edwards here: http://www.stopthehacker.com/tag/dean-edwards/

polonus

« Last Edit: December 08, 2011, 11:40:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Need help with JS:Redirector-H [Trj]
« Reply #8 on: December 08, 2011, 11:56:12 PM »
Sucuri says clean. I didn't find anything significant in the source code, but then again, I skimmed over it.
To think that was a counter (apps that count how many visits for a site). :-[


At least I can now identify some more malicious JavaScript coding!

Ty Sirmer & Polonus. :)

 ;)
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: Need help with JS:Redirector-H [Trj]
« Reply #9 on: December 09, 2011, 12:03:38 AM »
Hi Donovansrb10,

Sometimes malware is made up from two parts of innocent obfuscated script code and together with another piece of innocent code elsewhere on the website. It then becomes malicious code, when  the two script code parts act together as malware.
As you may have read from the link I gave by Dean Edwards:
Quote
The injected PHP code causes your WordPress installation to load the malware located inside a file named “wp_inc/upd.php” (usually in your “/tmp” folder). The malware then builds an Iframe element pointing to one of many different websites.
This was/is being used as a mass infection hack. Good avast detects it and the shield blocks it,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Need help with JS:Redirector-H [Trj]
« Reply #10 on: December 09, 2011, 12:42:39 AM »
This thing always has p,a,c,k,e,r in the coding, so it's easier to detect?
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: Need help with JS:Redirector-H [Trj]
« Reply #11 on: December 09, 2011, 04:09:12 PM »
Well this could help towards detecting, but there are good Dean Edwards packed and malicious Dean Edwards packed javascripts. With JS malware the main line of analysis is still being done manually - that is looking at the individual piece of malcode or recognizing a general attack sequence,
jsunpack and other tools can help towards de-obfuscation, but this deobfuscation is not needed if features are carefully extracted then obfuscated malicious code is found as easily (OCRF project - Eric Ching-Hao Ph.D),

polonus
« Last Edit: December 09, 2011, 04:11:08 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37603
  • Not a avast user
Re: Need help with JS:Redirector-H [Trj]
« Reply #12 on: December 09, 2011, 04:19:04 PM »
Norman lab confirms infected
Quote
baba3od.com.htm Processed - HTML/Agent.QS

darknight

  • Guest
Re: Need help with JS:Redirector-H [Trj]
« Reply #13 on: December 10, 2011, 12:26:14 AM »
Ah okay, I've notified my friend and linked him to this thread. Thank you so much guys for the help, really appreciate it!!! :)

girmy

  • Guest
Re: Need help with JS:Redirector-H [Trj]
« Reply #14 on: December 10, 2011, 11:35:19 AM »
hey
im the admin for this site

its only blog i dont know where the trojan come from i cheak all files also talk with support for the host company they also dont know

when i join my site from firefox i dont get any error only when i join it from exporler avast alret

also i cheak many online scan every thing is clean

can anyone help me how i remvoe this trojan and where can i find it