Tuesday, 13 March 2012

Fake Skype Vouchers website leads to Java Exploits

I stumbled upon a fake website that targets Skype users through vouchers or gift certificates. Below is the definition of Skype vouchers from their website:


Skype vouchers are electronic Skype Credit vouchers sold in various retail outlets. You don’t have to pay for the vouchers online and they make a great gift for family and friends so that you can keep in touch through Skype.

Vouchers are sometimes included with Skype accessories, or as part of a promotion.


Let's have a look of what is inside the said fake page:

[caption id="attachment_514" align="aligncenter" width="300" caption="Figure 1: Source of the fake website"][/caption]

Figure 1 shows the misleading title. You can also see a hidden iframe connecting to a different website.

Following the hidden iframe, we will now get an obfuscated script.

[caption id="attachment_512" align="aligncenter" width="300" caption="Figure 2: Obfuscated script"][/caption]

Some variables are highlighted in Figure 2. These variables will eventually become a window.eval() function when the script is executed. Now, let us modify the script in order for our script emulator to capture the result of the eval() function:

[caption id="attachment_510" align="aligncenter" width="300" caption="Figure 3: Modification part 1"][/caption]

Figure 3 shows that we need to remove some "if-statements" to make sure that our script will execute. You will also notice that one if-statement checks for the current year. The script will not run properly if it was not satisfied. In addition, proper deobfuscation of the script also depends on the value of the integer in the year check. We will tackle more about this in a while. For now, let's just deobfuscate this script.

[caption id="attachment_511" align="aligncenter" width="300" caption="Figure 4: Modification part 2"][/caption]

Figure 4 shows which variable will become the eval() function. After the modifications, execute the script and then dump the eval result. Figure 5 below will show you the result.

[caption id="attachment_513" align="aligncenter" width="300" caption="Figure 5: Deobfuscated script code"][/caption]

Now, you will see another set of hidden iframes that connect to another site. The said site will now load 2 malicious Java files:

[caption id="attachment_515" align="aligncenter" width="300" caption="Figure 6: Load Java applets"][/caption]

Sample 1: Java Exploit
MD5 hash: d3f933524c85c96a76f7ffd516d335c0
Virus Total scan result available here

Sample 2: Java Exploit
MD5 hash: 58db6e6e25d9b8e4742f2ef9b43c3818
Virus Total scan result available here

These Java files exploit the following vulnerability:


    CVE-2011-3544 - Oracle Java Applet Rhino Script Engine Remote Code Execution


Going back to the date check and value change, Figure 7 shows that we changed the integer value from "012" to "011".

[caption id="attachment_524" align="aligncenter" width="300" caption="Figure 7: Integer value modification"][/caption]

Now, let's dump the result to a file.

[caption id="attachment_521" align="aligncenter" width="300" caption="Figure 8: Result of the wrong value"][/caption]

You can see in Figure 8 that the result is now just a bunch of non-readable strings.

Source:
malwaredomainlist


References:
Skype
Virustotal
cve.mitre.org
Sourceforge

49 comments:

  1. Best gifts around...

    I was very happy to search out this net-site.I wished to thanks on your time for this wonderful learn!! I undoubtedly enjoying every little little bit of it and I have you bookmarked to take a look at new stuff you weblog post....

    ReplyDelete
  2. Original posted ......

    [...] You can find much more information here... [...]...

    ReplyDelete
  3. Amazing Simply...

    discover to ll the a This t Glimpse here web and definitely info all about you of know for site it who walk-through didn and ask wanted is you really this...

    ReplyDelete
  4. Great site to visit...

    The new Zune browser is [http://www.viagra.gd Viagra]surprisingly good, but not as good as the iPod's. It works well, but isn't as fast as Safari, and has a clunkier interface. If you occasionally plan on using the web browser that's not an issue, b...

    ReplyDelete
  5. you need a good friend...

    Clicking on one of those will center on that item, and another set of "neighbors" will come into view, allowing you to navigate around exploring by similar artists, songs, or users. Speaking of users, the Zune "Social" is also great fun, letting yo...

    ReplyDelete
  6. thanks a million...

    This is the right blog for anyone who wants to find out about this topic. You realize so much its almost hard to argue with you (not that I actually would want…HaHa). You definitely put a new spin on a topic thats been written about for years. Great st...

    ReplyDelete
  7. some friends cool offer!...

    Sorry for the huge review, but I'm really loving the new Zune, and hope this, as well as the excellent reviews some other people have written, will help you decide if it's the right choice for you....

    ReplyDelete
  8. Nice post...

    I learn something more challenging on different blogs everyday. It will always be stimulating to read content from other writers and practice a little something from their store. I’d prefer to use some with the content on my blog whether you don’t mind...

    ReplyDelete
  9. mangafox...

    mangafox,mangahere,mangakong,manga2u,Read your favorite manga online! Hundreds of high-quality free manga for you, with a list being updated daily. Naruto manga, Bleach manga, One Piece manga, Air Gear manga, Claymore manga, Fairy Tail manga, Inuyasha ...

    ReplyDelete
  10. juegos...

    Thanks for expressing your ideas. I might also like to convey that video games have been at any time evolving. Better technology and inventions have served create authentic and active games. Most of these entertainment video games were not actually sen...

    ReplyDelete
  11. Thank you !...

    I truly appreciate this post. I have been looking everywhere for this! Thank goodness I found it on Bing. You've made my day! Thank you again!...

    ReplyDelete
  12. Find more there:...

    Thank you, I have recently been searching for information approximately this topic for a while and yours is the best I have found out so far. However, what about the conclusion? Are you sure about the source?...

    ReplyDelete
  13. Porno Day...

    The "Pornosexday.com" is finer level in which you get footloose sex stamp with guaranteed outcome so we also wage videos for several categories that creates your mode for sex....

    ReplyDelete
  14. Buy Ambien...

    like subject new So something somebody starting nice something the original originality you that is read to little so website for internet this this with thank is this before dont a job the suppose to bringing this useful web some cool for find needed ...

    ReplyDelete
  15. adipex...

    It�s hard to find knowledgeable people on this topic, but you sound like you know what you�re talking about! Thanks...

    ReplyDelete
  16. http://www.adipex-guide.com...

    you are the best...

    ReplyDelete
  17. Viagra...

    issue encounter very I blog idea on in that that hit am the Really have the nail about outstanding must say intelligently educative impressed not a happy this entertaining let speaking that people both this rarely stumbled is Your across enough you I y...

    ReplyDelete
  18. percocet...

    Cheak it out !...

    ReplyDelete
  19. Define Batch Size: Select Environment Exctract: Clear! Enter Links Here, *** Without HTTP://WWW.***...

    This really answered my problem, thank you!...

    ReplyDelete
  20. Oxycodone...

    thanks for I d usually will I to me to people reading that here post is make do you think Also check have something not Which comment a enjoy with I allowing...

    ReplyDelete
  21. I've been browsing online more than three hours these days, but I never found any fascinating article like yours. It is lovely value sufficient for me. In my view, if all web owners and bloggers made good content as you probably did, the internet will be a lot more useful than ever before.

    ReplyDelete
  22. http://www.buyhydrocodoneovernight.com...

    making money online...

    ReplyDelete
  23. hydrocodone...

    great blog here...

    ReplyDelete
  24. levitra...

    I discovered your blog site on google and check a few of your early posts. Continue to keep up the very good operate. I just additional up your RSS feed to my MSN News Reader. Seeking forward to reading more from you later on!�...

    ReplyDelete
  25. http://www.codeineonlinepharmacy.com...

    thanks a million...

    ReplyDelete
  26. klonopin...

    Simply Amazing!...

    ReplyDelete
  27. http://www.buyxanaxonline.name...

    I�m impressed, I must say. Really rarely do I encounter a blog that�s both educative and entertaining, and let me tell you, you have hit the nail on the head. Your idea is outstanding; the issue is something that not enough people are speaking intellig...

    ReplyDelete
  28. http://www.adipex-usa.com...

    you need a good friend...

    ReplyDelete
  29. ambien...

    thanks a million...

    ReplyDelete
  30. Propecia...

    You are the best...

    ReplyDelete
  31. klonopin...

    I'll gear this review to 2 types of people: current Zune owners who are considering an upgrade, and people trying to decide between a Zune and an iPod. (There are other players worth considering out there, like the Sony Walkman X, but I hope this give...

    ReplyDelete
  32. Xenical...

    I something more Thanks little don other link different t mind I challenging to for use a a with whether everyday blog web something It blog Natually to their be sharing the from learn d stimulating blogs you some will your always from writers practice...

    ReplyDelete
  33. Cialis Online...

    telephone services with great service...

    ReplyDelete
  34. Cheap Viagra...

    you are the best...

    ReplyDelete
  35. Valium...

    Your place is valueble for me. Thanks!�...

    ReplyDelete
  36. cheap pr 7 domain Whilst I have to disagree on a few of the info, however I still truly liked it. I look forward to looking at far more of your posts....

    Whilst I have to disagree on a few of the info, however I still truly liked it. I look forward to looking at far more of your posts....

    ReplyDelete
  37. It's an awesome post designed for all the online viewers; they will get benefit from it I am sure.

    ReplyDelete
  38. The article is really very interesting! I will continue to try me here to keep you informed. Thank you!

    ReplyDelete
  39. Fuh ... done it. Set up Samsung Universal driver and
    home windows 8 considered it better motorist, though it never ever worked.
    It can be erased trough the Control board -) Programs and something.
    Then just follow Aaron post. Fun ... Thanks !!! ).

    ReplyDelete