Tag Archives: malicious

Black Hole Malvertisement Campaign

There’s yet another malvertisement that leads to Black Hole. This campaign is affecting a fairly popular site. The malicious script is linked from many of the site’s pages. Here’s a shot of the webpage’s source code which shows the initial … Continue reading

Posted in Exploit Packs, Malscript | Tagged , , , , | 1 Comment

Siberia Exploit Kit

Siberia Exploit Kit has been around for awhile but has been updated recently and the Javascript used to send users to its exploit page has changed. Here we see the original mess that conceals a redirect. After I remove all … Continue reading

Posted in Exploit Packs, Malscript | Tagged , | Comments Off on Siberia Exploit Kit

Deobfuscating Tricks

Deobfuscating malicious Javascript can be tricky at times. Luckily, there are several techniques researchers can use to decode Javascript that has been purposefully obscured to hide its real intentions. Here are the common techniques I use to deobfuscate malicious scripts … Continue reading

Posted in Malscript | Tagged , , , | Comments Off on Deobfuscating Tricks

Malicious Javascript Analysis II

This obfuscated Javascript came from a new, unknown exploit kit. There’s a large chunk of code that looks pretty scary! We can see a couple of things from this partial look at the script. It appears to be using AJAX … Continue reading

Posted in Malscript | Tagged , , | Comments Off on Malicious Javascript Analysis II

Malvertisement Leads to Dragon Pack

Dragon Pack is a new exploit kit that has hit the hacker scene. It sports only a handful of exploits but they are arguably the most successful ones. If nothing else, this pack looks very cool. Anyway, let’s take a … Continue reading

Posted in Exploit Packs, Malscript | Tagged , | Comments Off on Malvertisement Leads to Dragon Pack