Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Malignant JavaScript mutates to evade detection

ISC says hackers are creaing script code that is effectively undetectable by common types of malware scanners


Hackers have hit on a new technique for invading desktop computers via compromised Web sites, while avoiding anti-virus detectors, according to the SANS Institute.

SANS' Internet Storm Center (ISC) said on Thursday it has come across the attack on a compromised Web site, where an iframe was used to deploy various pieces of malicious code via JavaScript; iframes allow content from one Web site to be embedded in another Web site.

This technique itself isn't new, but researchers found that the server deploying the malicious JavaScript was heavily modifying it -- "obfuscating" it -- so as to be undetectable by anti-virus detectors, the ISC said. Moreover, the obfuscations were generated randomly and on the fly, according to ISC handler Bojan Zdrnja.

"What makes this new is that the hosting Web site generates this code dynamically," he wrote in an analysis. "Every time you request this Web page, it will use completely random names for all variables and functions ... changing variable and function names even causes the payload information to change."

The technique makes the script code effectively undetectable by common types of malware scanners, Zdrnja said.

"Such heavy obfuscation makes signature-based detection much more difficult, if not impossible," he wrote. None of the anti-virus programs Zdrnja tested were able to detect the modified code.

The code contains what Zdrnja called a "typical" set of exploits, making use of known vulnerabilities in ADODB, QuickTime, WinZip, and other software.

The code also included a less well-known, but highly pernicious exploit for the NCTAudioFile2 ActiveX control, Zdrnja said.

"A fully working exploit was publicly released in April, and what's worse is that the affected ActiveX control is delivered with dozens of popular audio/video applications," Zdrnja wrote.


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





THE TOP THREE WAYS TO CUT COSTS IN 2009
With the current economic environment, organizations are looking for ways to cut costs. With Oracle Content Management, you can cut costs in three ways in 2009: consolidation, process automation and compliance. Learn more from this webcast sponsored by Oracle.

»  Click here to view this Webcast
  Network Security Solutions Guide
Network security is comprised of so much more than protecting just one or two PCs. And network security management can be different based on your situation. Read this Solutions Guide to find the best ways to protect your entire network, from individual PCs to network-attached storage and more. Sponsored by ISC2

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 12/01/2008

Microsoft, Yahoo dismiss report of a search deal, British prosecutors ...

 
 
 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity