Tag Archives: obfuscated javascript

Revelo Updated

I’ve been noticing obfuscated Javascript using a function that returns the deobfuscated result more and more lately so I added a new method to catch this. Here’s an obfuscated script. It’s not that difficult but it does look intimidating! First … Continue reading

Posted in Malscript, Tools | Tagged , | Comments Off on Revelo Updated

Another Clever Drive-By

This is yet another drive-by that was challenging to find. It delivered payloads from two different exploit packs making it very cruel too. Below is the infected webpage. I kept visiting this page, scrolling up and down, and nothing happened … Continue reading

Posted in Exploit Packs, Malscript | Tagged , , , | 166 Comments

New Exploit Pack Spotted

Another new exploit pack has been found in the wild. This pack uses two interesting methods to obfuscate its contents. Both methods aren’t brand new but interesting nonetheless. Let’s have a closer look… Here’s the infection chain: tmkgm.lflinkup.com/main.php alpkfbtgy.lflinkup.com/3227fyw/024776ygcgd.asp?1 alpkfbtgy.lflinkup.com/06592657829ja/qrsop326821?1 … Continue reading

Posted in Exploit Packs, Malscript | Tagged , | 1 Comment

New Exploit Pack

A new exploit pack is being used in the wild. This one was linked to malvertisements that were appearing on popular sites. Here’s one of them: Here’s the infection chain: Let’s have a closer look at that second file. At … Continue reading

Posted in Exploit Packs, Malscript | Tagged , | 3 Comments

Custom Base64 Decoder

There’s another new exploit pack making its round. Seems to be quite pervasive as I’m seeing its redirect code on many compromised sites. Here’s the redirection script: And this is the main script of the exploit pack that awaits your … Continue reading

Posted in Exploit Packs, Malscript, Tools | Tagged , , | 3 Comments