Author Topic: Website Infected with HTML:IFrame-MP [Trj]  (Read 8432 times)

0 Members and 1 Guest are viewing this topic.

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Website Infected with HTML:IFrame-MP [Trj]
« on: September 07, 2010, 10:16:05 AM »
Dear All,

According to avast! antivirus this website : hxxtp://www.takemeoutindonesia.com was infected by HTML:IFrame-MP [Trj.

And for some web scan tool there is nothing infected on this website :

http://www.virustotal.com/url-scan/report.html?id=af318043253af82e9a9e7d859c259b3b-1283838999
http://scanner2.novirusthanks.org/analysis/73e3a3ed9abcb01400707e45b1ef1e63/d3d3LXRha2VtZW91dGluZG9uZXNpYS1jb20=/

But at W.O.T i found this website detected as infected and have a poor reputation :
http://www.mywot.com/en/scorecard/www.takemeoutindonesia.com

And same with JSunpack indicated that there is a hidden malicious software inside of this website :

http://jsunpack.jeek.org/filescount.html

Just want to share, if there's anybody in here can help me to reveal out this entertainment show website it would very helpful to advice anyone to access this website.

cheers,
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Stewdza

  • Guest
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #2 on: September 07, 2010, 10:32:47 AM »
It is a Virus, so even GData said that is a trojan horse. Trust avast! always.

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #3 on: September 07, 2010, 10:42:18 AM »
It is a Virus, so even GData said that is a trojan horse. Trust avast! always.

Hi Stewdza,

Yes i trust, but in depth i would like to see in details what is the parameter which caused this website detected was infected by a trojan.

cheers,
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Stewdza

  • Guest
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #4 on: September 07, 2010, 11:12:45 AM »
It is a Virus, so even GData said that is a trojan horse. Trust avast! always.

Hi Stewdza,

Yes i trust, but in depth i would like to see in details what is the parameter which caused this website detected was infected by a trojan.

cheers,
Hi, i understand your reason. Probalby it is deep hiden malware (some part of the code is malicious). Keep studing until you find right answer on your question.
Regards.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #5 on: September 07, 2010, 11:21:09 AM »
Quote
It is a Virus, so even GData said that is a trojan horse. Trust avast! always
That is not a supprise since GData is using two virus engines and one is avast! the other is bitdefender

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #6 on: September 07, 2010, 04:10:24 PM »
Well there is something at the very least suspect about that .js file chrisdomroll.js on the hxxp://www.takemeoutindonesia.com, site.

The last very long line of obfuscated javascript in this file creates a hidden iframe to an unknown URL, see image of decoded javascript file.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #7 on: September 07, 2010, 06:04:06 PM »
Hi YantoChiang,

This scorecard is not very encouraging: http://www.mywot.com/en/scorecard/takemeoutindonesia.com
The analysis of the code DavidR mentioned: http://jsunpack.jeek.org/dec/go?report=25f769ce9430a29a831d8685cb1def271b63af1b
Similar report on this from another site with christdomroll.js rollover iFrame code, which was apparently hacked: http://newverhost.com/reports/83/87/791/nelleandlizzy_com.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #8 on: September 08, 2010, 07:46:25 AM »
Hi DavidR and Polonus,

We are many thanks for your kindly details observation,

Since i didn't found any result from JSunPack yesterday.

But now after your guys explained in details information, that is very helpful to me. And since yesterday i already send email to their corporate regarding to this matters.

cheers,

Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #9 on: September 08, 2010, 03:44:15 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #10 on: September 17, 2010, 05:11:16 AM »
Hi David and Polonus,

Until today their management still not respond or changed their script yet even i already send warning e-mail to them.

cheers,
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #11 on: September 17, 2010, 09:21:30 AM »
Some people are slow to respond or even believe they are infected, even in the face of the evidence. Just goes how much they value their customers or potential customers, companies like this frequently only realise too late.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #12 on: September 18, 2010, 05:56:50 AM »
Hi David,

Thanks for your kindly advise...

cheers,
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Website Infected with HTML:IFrame-MP [Trj]
« Reply #13 on: September 18, 2010, 03:28:37 PM »
No problem.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security