Skype vouchers are electronic Skype Credit vouchers sold in various retail outlets. You don’t have to pay for the vouchers online and they make a great gift for family and friends so that you can keep in touch through Skype.
Vouchers are sometimes included with Skype accessories, or as part of a promotion.
Let's have a look of what is inside the said fake page:
[caption id="attachment_514" align="aligncenter" width="300" caption="Figure 1: Source of the fake website"]
[/caption]Figure 1 shows the misleading title. You can also see a hidden iframe connecting to a different website.
Following the hidden iframe, we will now get an obfuscated script.
[caption id="attachment_512" align="aligncenter" width="300" caption="Figure 2: Obfuscated script"]
[/caption]Some variables are highlighted in Figure 2. These variables will eventually become a window.eval() function when the script is executed. Now, let us modify the script in order for our script emulator to capture the result of the eval() function:
[caption id="attachment_510" align="aligncenter" width="300" caption="Figure 3: Modification part 1"]
[/caption]Figure 3 shows that we need to remove some "if-statements" to make sure that our script will execute. You will also notice that one if-statement checks for the current year. The script will not run properly if it was not satisfied. In addition, proper deobfuscation of the script also depends on the value of the integer in the year check. We will tackle more about this in a while. For now, let's just deobfuscate this script.
[caption id="attachment_511" align="aligncenter" width="300" caption="Figure 4: Modification part 2"]
[/caption]Figure 4 shows which variable will become the eval() function. After the modifications, execute the script and then dump the eval result. Figure 5 below will show you the result.
[caption id="attachment_513" align="aligncenter" width="300" caption="Figure 5: Deobfuscated script code"]
[/caption]Now, you will see another set of hidden iframes that connect to another site. The said site will now load 2 malicious Java files:
[caption id="attachment_515" align="aligncenter" width="300" caption="Figure 6: Load Java applets"]
[/caption]Sample 1: Java Exploit
MD5 hash: d3f933524c85c96a76f7ffd516d335c0
Virus Total scan result available here
Sample 2: Java Exploit
MD5 hash: 58db6e6e25d9b8e4742f2ef9b43c3818
Virus Total scan result available here
These Java files exploit the following vulnerability:
CVE-2011-3544 - Oracle Java Applet Rhino Script Engine Remote Code Execution
Going back to the date check and value change, Figure 7 shows that we changed the integer value from "012" to "011".
[caption id="attachment_524" align="aligncenter" width="300" caption="Figure 7: Integer value modification"]
[/caption]Now, let's dump the result to a file.
[caption id="attachment_521" align="aligncenter" width="300" caption="Figure 8: Result of the wrong value"]
[/caption]You can see in Figure 8 that the result is now just a bunch of non-readable strings.
Source:
malwaredomainlist
References:
Skype
Virustotal
cve.mitre.org
Sourceforge
Best gifts around...
ReplyDeleteI was very happy to search out this net-site.I wished to thanks on your time for this wonderful learn!! I undoubtedly enjoying every little little bit of it and I have you bookmarked to take a look at new stuff you weblog post....
Original posted ......
ReplyDelete[...] You can find much more information here... [...]...
Amazing Simply...
ReplyDeletediscover to ll the a This t Glimpse here web and definitely info all about you of know for site it who walk-through didn and ask wanted is you really this...
ambien...
ReplyDeleteSimply Amazing...
Great site to visit...
ReplyDeleteThe new Zune browser is [http://www.viagra.gd Viagra]surprisingly good, but not as good as the iPod's. It works well, but isn't as fast as Safari, and has a clunkier interface. If you occasionally plan on using the web browser that's not an issue, b...
you need a good friend...
ReplyDeleteClicking on one of those will center on that item, and another set of "neighbors" will come into view, allowing you to navigate around exploring by similar artists, songs, or users. Speaking of users, the Zune "Social" is also great fun, letting yo...
thanks a million...
ReplyDeleteThis is the right blog for anyone who wants to find out about this topic. You realize so much its almost hard to argue with you (not that I actually would want…HaHa). You definitely put a new spin on a topic thats been written about for years. Great st...
some friends cool offer!...
ReplyDeleteSorry for the huge review, but I'm really loving the new Zune, and hope this, as well as the excellent reviews some other people have written, will help you decide if it's the right choice for you....
Nice post...
ReplyDeleteI learn something more challenging on different blogs everyday. It will always be stimulating to read content from other writers and practice a little something from their store. I’d prefer to use some with the content on my blog whether you don’t mind...
mangafox...
ReplyDeletemangafox,mangahere,mangakong,manga2u,Read your favorite manga online! Hundreds of high-quality free manga for you, with a list being updated daily. Naruto manga, Bleach manga, One Piece manga, Air Gear manga, Claymore manga, Fairy Tail manga, Inuyasha ...
juegos...
ReplyDeleteThanks for expressing your ideas. I might also like to convey that video games have been at any time evolving. Better technology and inventions have served create authentic and active games. Most of these entertainment video games were not actually sen...
Thank you !...
ReplyDeleteI truly appreciate this post. I have been looking everywhere for this! Thank goodness I found it on Bing. You've made my day! Thank you again!...
propecia...
ReplyDeletegreat blog here...
Find more there:...
ReplyDeleteThank you, I have recently been searching for information approximately this topic for a while and yours is the best I have found out so far. However, what about the conclusion? Are you sure about the source?...
Porno Day...
ReplyDeleteThe "Pornosexday.com" is finer level in which you get footloose sex stamp with guaranteed outcome so we also wage videos for several categories that creates your mode for sex....
Buy Ambien...
ReplyDeletelike subject new So something somebody starting nice something the original originality you that is read to little so website for internet this this with thank is this before dont a job the suppose to bringing this useful web some cool for find needed ...
adipex...
ReplyDeletesome friends cool offer!...
adderall...
ReplyDeleteNice post...
adipex...
ReplyDeleteIt�s hard to find knowledgeable people on this topic, but you sound like you know what you�re talking about! Thanks...
ambien...
ReplyDeletegreat blog here...
viagra...
ReplyDeletegreat blog here...
http://www.adipex-guide.com...
ReplyDeleteyou are the best...
Viagra...
ReplyDeleteissue encounter very I blog idea on in that that hit am the Really have the nail about outstanding must say intelligently educative impressed not a happy this entertaining let speaking that people both this rarely stumbled is Your across enough you I y...
percocet...
ReplyDeleteCheak it out !...
Define Batch Size: Select Environment Exctract: Clear! Enter Links Here, *** Without HTTP://WWW.***...
ReplyDeleteThis really answered my problem, thank you!...
Buy Propecia...
ReplyDeletePrices Best...
Oxycodone...
ReplyDeletethanks for I d usually will I to me to people reading that here post is make do you think Also check have something not Which comment a enjoy with I allowing...
I've been browsing online more than three hours these days, but I never found any fascinating article like yours. It is lovely value sufficient for me. In my view, if all web owners and bloggers made good content as you probably did, the internet will be a lot more useful than ever before.
ReplyDeletehttp://www.buyhydrocodoneovernight.com...
ReplyDeletemaking money online...
cialis...
ReplyDeletegreat blog here...
hydrocodone...
ReplyDeletegreat blog here...
levitra...
ReplyDeleteI discovered your blog site on google and check a few of your early posts. Continue to keep up the very good operate. I just additional up your RSS feed to my MSN News Reader. Seeking forward to reading more from you later on!�...
http://www.codeineonlinepharmacy.com...
ReplyDeletethanks a million...
klonopin...
ReplyDeleteSimply Amazing!...
http://www.buyxanaxonline.name...
ReplyDeleteI�m impressed, I must say. Really rarely do I encounter a blog that�s both educative and entertaining, and let me tell you, you have hit the nail on the head. Your idea is outstanding; the issue is something that not enough people are speaking intellig...
http://www.adipex-usa.com...
ReplyDeleteyou need a good friend...
ambien...
ReplyDeleteCheak it out !...
ambien...
ReplyDeletethanks a million...
Propecia...
ReplyDeleteYou are the best...
klonopin...
ReplyDeleteI'll gear this review to 2 types of people: current Zune owners who are considering an upgrade, and people trying to decide between a Zune and an iPod. (There are other players worth considering out there, like the Sony Walkman X, but I hope this give...
Xenical...
ReplyDeleteI something more Thanks little don other link different t mind I challenging to for use a a with whether everyday blog web something It blog Natually to their be sharing the from learn d stimulating blogs you some will your always from writers practice...
Cialis Online...
ReplyDeletetelephone services with great service...
Cialis...
ReplyDeletegreat site dod...
Cheap Viagra...
ReplyDeleteyou are the best...
Valium...
ReplyDeleteYour place is valueble for me. Thanks!�...
cheap pr 7 domain Whilst I have to disagree on a few of the info, however I still truly liked it. I look forward to looking at far more of your posts....
ReplyDeleteWhilst I have to disagree on a few of the info, however I still truly liked it. I look forward to looking at far more of your posts....
It's an awesome post designed for all the online viewers; they will get benefit from it I am sure.
ReplyDeleteThe article is really very interesting! I will continue to try me here to keep you informed. Thank you!
ReplyDeleteFuh ... done it. Set up Samsung Universal driver and
ReplyDeletehome windows 8 considered it better motorist, though it never ever worked.
It can be erased trough the Control board -) Programs and something.
Then just follow Aaron post. Fun ... Thanks !!! ).