Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Another Government Website Hacked

    This is to confirm a report from Websense about the compromised official website of Syrian Embassy located in London. Indeed, there are three obfuscated iframes found in the site.

    The following is a sample obfuscated script found in the compromised page:

    1.JPG

    Deobfuscating the said scripts we get the following URLs:

    • hxxp://0ki.ru{blocked}/index.php
    • hxxp://sicil.info{blocked}/index.php
    • hxxp://x12345.or/{blocked}ounter.php?out=1189360677 (a zero-byte file)

    Initial analysis of the first URL, it seems that it accepts country code as an argument, thus country checking is most probably employed. This is already detected as JS_PSYME.ANT. The second URL contains another iframe which leads to a URL containing the exploit kit (most probably Icepack). The exploit kit employs OS detection, web browser detection, and contains several exploits targeting web browsers and web browser plug-in. This will try to exploit several vulnerabilities to download and execute a file to be detected as TROJ_SMALL.KYZ. The exploit kit will be detected as JS_PSYME.ADQ.

    2.JPG

    3.bmp

    The third URL just contains a zero-byte file.The malicious files are already being processed and the malicious URLs are submitted for blocking.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    One Response to “Another Government Website Hacked”

    Trackbacks

    1. Posibil HACK - verificati-va siteurile


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice