Did the GBS Penultimate Archive get infected?

You can talk about almost anything that you want to on this board.

Moderator: Moderators

Post Reply
Drag
Posts: 1350
Joined: Mon Sep 27, 2004 2:57 pm
Contact:

Did the GBS Penultimate Archive get infected?

Post by Drag »

I just browsed there right now, and I received a warning from my antivirus that an infected file got dumped into Firefox's cache. Moreover, it seems to have launched Acrobat Reader for unknown reasons. AdBlock also listed a few unfamiliar sites having embeds and iframes in the page, though I didn't have time to write them down or anything.
ugetab
Posts: 335
Joined: Sat Oct 29, 2005 12:03 am
Contact:

Post by ugetab »

Yes. The javascript being generated is trying to write out a .exe file.

http://pastebin.com/d17168fc3
NSFs I've ripped:
http://www.angelfire.com/nc/ugetab/

A Searchable list of NSFs from other sites. In Internet Explorer, go to Edit>Find (on This Page)...
http://www.angelfire.com/nc/ugetab/NSFList.txt
Knurek
Posts: 137
Joined: Tue Jan 31, 2006 5:43 am

Re: Did the GBS Penultimate Archive get infected?

Post by Knurek »

Drag wrote:I just browsed there right now, and I received a warning from my antivirus that an infected file got dumped into Firefox's cache. Moreover, it seems to have launched Acrobat Reader for unknown reasons. AdBlock also listed a few unfamiliar sites having embeds and iframes in the page, though I didn't have time to write them down or anything.
Quite possible, unfortunately (I had to remove some virii links from Hoot Archive files).

Dunno what's the cause though... I'll see if there are any leaks and try to patch things up if possible.

//Edit

Removed the malware link, removed the page counter from Hoot Archive. Hope this was the cause...
ugetab
Posts: 335
Joined: Sat Oct 29, 2005 12:03 am
Contact:

Post by ugetab »

If you viewed that page with Internet Explorer, you're likely infected. I modified it, and used some NoScript protection to prevent the PDF part from being downloaded while I worked out the code to put it to a text box.
NSFs I've ripped:
http://www.angelfire.com/nc/ugetab/

A Searchable list of NSFs from other sites. In Internet Explorer, go to Edit>Find (on This Page)...
http://www.angelfire.com/nc/ugetab/NSFList.txt
Knurek
Posts: 137
Joined: Tue Jan 31, 2006 5:43 am

Post by Knurek »

ugetab wrote:If you viewed that page with Internet Explorer, you're likely infected. I modified it, and used some NoScript protection to prevent the PDF part from being downloaded while I worked out the code to put it to a text box.
That and everything hosted on Hoot Archive account (so, GBS site, kingshriek's rip site, think that's all).

I've removed malware links from all sites, let's hope that's enough.
Drag
Posts: 1350
Joined: Mon Sep 27, 2004 2:57 pm
Contact:

Post by Drag »

So it was a javascript giving out the virus, huh?

I should disable javascript a bit more than I actually do...

Thank you very much for cleaning things up. :)
ugetab
Posts: 335
Joined: Sat Oct 29, 2005 12:03 am
Contact:

Post by ugetab »

I used FF with Noscript. I could run the Javascript and the Noscript plugin still killed the PDF execution. Since I knew it was malware from the start, I checked for write logs by Firefox, and looked for stuff going wrong, but it looks like it couldn't work even with permission to execute.
NSFs I've ripped:
http://www.angelfire.com/nc/ugetab/

A Searchable list of NSFs from other sites. In Internet Explorer, go to Edit>Find (on This Page)...
http://www.angelfire.com/nc/ugetab/NSFList.txt
Post Reply