Avast WEBforum

Other => Viruses and worms => Topic started by: Henrique - RJ on July 03, 2011, 07:30:04 PM

Title: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 03, 2011, 07:30:04 PM
The attack is affecting millions of Brazilians in Orkut.

The cracker, in the phishing site, asks the person run the code in the browser:

Any antivirus is detecting.
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on July 03, 2011, 08:04:16 PM
dont post potentially malwarecode in the forum, as this can/will trigg AV warnings if/when detected by any AV to those entering the forum
so please remove the code, if you want to post it take a picture of it and post the pic

Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on July 03, 2011, 08:35:01 PM
VirusTotal 0/42
http://www.virustotal.com/file-scan/report.html?id=f6789f5ca78162bf54030af39980ba920e2c19ba80cbc662b59af87590811787-1309717773
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 03, 2011, 08:44:14 PM
Exact, any antivirus detects it for the time being ...

Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: polonus on July 04, 2011, 12:07:15 AM
Hi  Henrique - RJ,

There is a write-up on this threat which can be read here: http://www.knowthetech.com/2010/11/orkut-infected-with-malware-again.html
More to be found on the google help page here: http://www.google.com/support/forum/p/orkut/thread?tid=3c422fbd51d16b83&hl=en
MBAM, SAS and HitmanPro Scans are being adviced in the link given. The use of HitmanPro should only be performed under professional guidance, because if not properly handled it could ruin your operational system,

polonus
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 04, 2011, 06:17:08 AM
Hi  Henrique - RJ,

There is a write-up on this threat which can be read here: http://www.knowthetech.com/2010/11/orkut-infected-with-malware-again.html
More to be found on the google help page here: http://www.google.com/support/forum/p/orkut/thread?tid=3c422fbd51d16b83&hl=en
MBAM, SAS and HitmanPro Scans are being adviced in the link given. The use of HitmanPro should only be performed under professional guidance, because if not properly handled it could ruin your operational system,

polonus

But my intention to open this topic is that the signature is created for the database so that Avast detects this.
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on July 05, 2011, 09:04:44 AM
NORMAN analysis


Quote
Hi,

"Script.txt" contins a url (hxxp://chiipssgoogle.hd1.in/cod2.txt) to download another obfucated script to work on Orkut profile. Further it redirects to fake  URL.

Readable format of this script is at: hxxp://pastebin.com/EtjRJ3CB

"script.txt"  would be detected as "JS/Redirector.CO"

Thanks
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 05, 2011, 03:42:21 PM
Avast team seems not be interested.
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: polonus on July 05, 2011, 04:29:30 PM
Hi Henrique - RJ,

Did you sent your observations and the malcode link to virus AT avast dot com via mail?
If so they will not send you a personal notification, but it is my experience that they take all that is being sent there very, very seriously. Especially where Brazilian banking trojans are concerned they should be extra watchful, seen to the overal avast detection rate that is open to some real improvement, so stay optimistic, Henrique - RJ. Avast never had let us down, so wait for detection...

polonus
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 05, 2011, 07:49:15 PM
Yes I sent many days ago ...
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 09, 2011, 11:18:43 PM
and avast still not detect the script ...

The avast team has no interest !
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on July 09, 2011, 11:30:28 PM
can you post the link to the scan result ?
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 09, 2011, 11:37:31 PM
Of VirusTotal ?
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on July 09, 2011, 11:44:08 PM
yes if that is where you scanned it
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 09, 2011, 11:55:22 PM
http://www.virustotal.com/file-scan/report.html?id=7c2f842efcd6903cc71985c239136ac7bab5506b6ab0b8bb26ee7d60495c8ad2-1310247801

And should have many malicious scripts of Orkut that avast does not detect and the avast team has not interest ...

Avira and Norman already detecting !
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 11, 2011, 02:33:36 PM
Too late ...

The brazilians crackers are no longer attacking on Orkut.

Avast is still not detecting ...

 :'(
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on July 31, 2011, 06:50:50 AM
And Avast is still not detecting ...

 :'(  :'(  :'(
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 07:25:40 PM
Hello virus analisty !!!

The script it's still not detected by Avast.

Please !
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: essexboy on September 26, 2011, 07:26:24 PM
Do you have a copy of the file to give to Avast ?
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 07:30:47 PM
Yes

Attached
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: essexboy on September 26, 2011, 07:38:03 PM
Could you now remove it please from your post

Also it is just a text file - how is it delivered ?
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: REDACTED on September 26, 2011, 07:39:22 PM
Yes

Attached



Ваш запрос был проанализирован. Присланный Вами файл не представляет угрозы.




Спасибо за сотрудничество.

To reсeive notifications in English, send a blank email to lang@rt-web.dev.drweb.com

--
С уважением,
Служба вирусного мониторинга ООО "Доктор Веб"


-------------------Запрос--------------------------------------

This is software generated mail message on behalf of virus hunters activity.
Category: SUSPICIOUS FILE
File:     cod2.txt
MD5:      f54a43ab282cc9dbf68ca7ca53058dc2



Your request has been analyzed. Sent you the file is not a threat.
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 07:45:15 PM
Could you now remove it please from your post

Also it is just a text file - how is it delivered ?

Yes, look a first post for this topic: http://forum.avast.com/index.php?topic=80972.msg662188#msg662188


Yes

Attached



Ваш запрос был проанализирован. Присланный Вами файл не представляет угрозы.




Спасибо за сотрудничество.

To reсeive notifications in English, send a blank email to lang@rt-web.dev.drweb.com

--
С уважением,
Служба вирусного мониторинга ООО "Доктор Веб"


-------------------Запрос--------------------------------------

This is software generated mail message on behalf of virus hunters activity.
Category: SUSPICIOUS FILE
File:     cod2.txt
MD5:      f54a43ab282cc9dbf68ca7ca53058dc2



Your request has been analyzed. Sent you the file is not a threat.

Look please

http://www.virustotal.com/file-scan/report.html?id=7c2f842efcd6903cc71985c239136ac7bab5506b6ab0b8bb26ee7d60495c8ad2-1317057727


Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: REDACTED on September 26, 2011, 08:46:29 PM
http://jsunpack.jeek.org/dec/go?report=71691e5489134cc18fced26195f3b8e722883747

URL   
hххp://www.myspace.com/570785160/blog/543467696/?6388   

Status
(referer=www.google.com/trends/hottrends)failure: HTTP Error 404: Not Found


Сurrently do not introduce to the threat.
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 09:11:30 PM
Ok Ok

I understand.

But the code in txt is jscript redirect !

"HTTP Error 404: Not Found" because it was removed (three months ago).

Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: REDACTED on September 26, 2011, 09:24:48 PM
Ok Ok

I understand.

But the code in txt is a redirect !

"HTTP Error 404: Not Found" because it was removed (three months ago).




Well this is a question for analysts avast .. but they rarely comment on that here, but note that few are added to the database, I think there is no reason to worry) How is Brazil? heat?
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Pondus on September 26, 2011, 09:33:03 PM
see reply #4 and #6   
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 09:41:09 PM
Ok Ok

I understand.

But the code in txt is a redirect !

"HTTP Error 404: Not Found" because it was removed (three months ago).




Well this is a question for analysts avast .. but they rarely comment on that here, but note that few are added to the database, I think there is no reason to worry) How is Brazil? heat?

Ok

oohh no much heat here today in Rio de Janeiro city: 22ºC

Child's photo very beautiful !
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: REDACTED on September 26, 2011, 09:56:41 PM
http://www.earthcam.com/brazil/riodejaneiro/


Красиво - beautifully :)
Title: Re: Code executed in the browser hijacks Orkut in Brazil
Post by: Henrique - RJ on September 26, 2011, 10:34:12 PM
http://www.earthcam.com/brazil/riodejaneiro/


Красиво - beautifully :)

 :)