Author Topic: Code executed in the browser hijacks Orkut in Brazil  (Read 10013 times)

0 Members and 1 Guest are viewing this topic.

Henrique - RJ

  • Guest
Code executed in the browser hijacks Orkut in Brazil
« on: July 03, 2011, 07:30:04 PM »
The attack is affecting millions of Brazilians in Orkut.

The cracker, in the phishing site, asks the person run the code in the browser:

Any antivirus is detecting.
« Last Edit: July 03, 2011, 08:21:52 PM by Henrique - RJ »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #1 on: July 03, 2011, 08:04:16 PM »
dont post potentially malwarecode in the forum, as this can/will trigg AV warnings if/when detected by any AV to those entering the forum
so please remove the code, if you want to post it take a picture of it and post the pic



Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #3 on: July 03, 2011, 08:44:14 PM »
Exact, any antivirus detects it for the time being ...

« Last Edit: July 03, 2011, 08:45:59 PM by Henrique - RJ »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #4 on: July 04, 2011, 12:07:15 AM »
Hi  Henrique - RJ,

There is a write-up on this threat which can be read here: http://www.knowthetech.com/2010/11/orkut-infected-with-malware-again.html
More to be found on the google help page here: http://www.google.com/support/forum/p/orkut/thread?tid=3c422fbd51d16b83&hl=en
MBAM, SAS and HitmanPro Scans are being adviced in the link given. The use of HitmanPro should only be performed under professional guidance, because if not properly handled it could ruin your operational system,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #5 on: July 04, 2011, 06:17:08 AM »
Hi  Henrique - RJ,

There is a write-up on this threat which can be read here: http://www.knowthetech.com/2010/11/orkut-infected-with-malware-again.html
More to be found on the google help page here: http://www.google.com/support/forum/p/orkut/thread?tid=3c422fbd51d16b83&hl=en
MBAM, SAS and HitmanPro Scans are being adviced in the link given. The use of HitmanPro should only be performed under professional guidance, because if not properly handled it could ruin your operational system,

polonus

But my intention to open this topic is that the signature is created for the database so that Avast detects this.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #6 on: July 05, 2011, 09:04:44 AM »
NORMAN analysis


Quote
Hi,

"Script.txt" contins a url (hxxp://chiipssgoogle.hd1.in/cod2.txt) to download another obfucated script to work on Orkut profile. Further it redirects to fake  URL.

Readable format of this script is at: hxxp://pastebin.com/EtjRJ3CB

"script.txt"  would be detected as "JS/Redirector.CO"

Thanks

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #7 on: July 05, 2011, 03:42:21 PM »
Avast team seems not be interested.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #8 on: July 05, 2011, 04:29:30 PM »
Hi Henrique - RJ,

Did you sent your observations and the malcode link to virus AT avast dot com via mail?
If so they will not send you a personal notification, but it is my experience that they take all that is being sent there very, very seriously. Especially where Brazilian banking trojans are concerned they should be extra watchful, seen to the overal avast detection rate that is open to some real improvement, so stay optimistic, Henrique - RJ. Avast never had let us down, so wait for detection...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #9 on: July 05, 2011, 07:49:15 PM »
Yes I sent many days ago ...

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #10 on: July 09, 2011, 11:18:43 PM »
and avast still not detect the script ...

The avast team has no interest !

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #11 on: July 09, 2011, 11:30:28 PM »
can you post the link to the scan result ?

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #12 on: July 09, 2011, 11:37:31 PM »
Of VirusTotal ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #13 on: July 09, 2011, 11:44:08 PM »
yes if that is where you scanned it

Henrique - RJ

  • Guest
Re: Code executed in the browser hijacks Orkut in Brazil
« Reply #14 on: July 09, 2011, 11:55:22 PM »
http://www.virustotal.com/file-scan/report.html?id=7c2f842efcd6903cc71985c239136ac7bab5506b6ab0b8bb26ee7d60495c8ad2-1310247801

And should have many malicious scripts of Orkut that avast does not detect and the avast team has not interest ...

Avira and Norman already detecting !