Category Archives: Malscript

Deobfuscating Magento Guruincsite Javascript

I saw this blog post by the super talented guys over at Sucuri and thought that it was just another URL redirection script hiding behind escaped characters but it turned out to be better than that. Here’s what the script … Continue reading

Posted in Malscript, Tools | Tagged , , | Comments Off on Deobfuscating Magento Guruincsite Javascript

New Javascript Deobfuscator Tool

This particular spam page redirect was brought to my attention by a colleague because it was getting past the web filters using Javascript obfuscation. In one version, the landing page uses a meta refresh tag. I guess it was getting … Continue reading

Posted in Malscript, Tools | Tagged , | Comments Off on New Javascript Deobfuscator Tool

Webshell with a Booby Trap

I came across three interesting PHP scripts that were presumably dropped by the same attacker. Perhaps this is old news but it’s something new to me. Here’s the first one which looks innocent enough. However, if you put in the … Continue reading

Posted in Malscript | Tagged , , | Comments Off on Webshell with a Booby Trap

Converter Updated

The latest version includes several new features which I’d like to highlight here: Enhanced Range Search/Replace The feature can be found by going to this menu item under Tools: You can now add incrementers as a text replacement as seen … Continue reading

Posted in Malscript, Tools | Tagged , , , , , | Comments Off on Converter Updated

Malicious Word Macro Caught Using Sneaky Trick

There has been a slew of malicious Word documents attached to email purporting to be invoices, receipts, etc. This particular one caught my eye but I’m not sure if this is an old trick. I just haven’t seen this method … Continue reading

Posted in Malicious Email, Malscript | Tagged , , , , , , | Comments Off on Malicious Word Macro Caught Using Sneaky Trick