PaulDotCom mailing list archives

phishing question

From: dshpritz at (David Shpritz)
Date: Wed, 2 Dec 2009 12:44:00 -0500

Hey David,
Would you mind telling us what method you used to deobfuscate the scripts?  Usually I have done these by hand or used 
Malzilla, but I'm always looking for new methods.  Thanks!

David Shpritz

-----Original Message-----
From: pauldotcom-bounces at [mailto:pauldotcom-bounces at] On Behalf Of 
David Auclair
Sent: Wednesday, December 02, 2009 9:45 AM
To: PaulDotCom Security Weekly Mailing List
Subject: Re: [Pauldotcom] phishing question

It looks like the javascript on the page you mentioned leads to this page:
hxxp://www . businessinabox . com . au/357/?go

Which is full of more obfuscated javascript, which leads to sites such as:
hxxp:// /

Which seems to have 'you need to update your flash player' image, linking to setup.exe

According to virustotal, the setup.exe contains koobface:


-----Original Message-----
From: pauldotcom-bounces at [mailto:pauldotcom-bounces at] On Behalf
Of Chris Blazek
Sent: Wednesday, December 02, 2009 12:04 AM
To: PaulDotCom Security Weekly Mailing List
Subject: Re: [Pauldotcom] phishing question

   Yeah, I had the user change all passwords from the email account to
fb. I had tried googling for that 1st part of the address, hoping
someone had posted something about it. That came up empty.
I tried to get malzilla to decode it, but I really have little
experience decoding JavaScript like that.
I'll try looking for deobfuscaters to see if something else can decode
Sorry for the typos in the original email. :)

Thanks for the help!


On Dec 1, 2009, at 8:47 PM, PJ McGarvey <pj_mcgarvey at> wrote:

Well, if you mean what does the obfuscated code do, there are a few
sites I've used that can "de-obfuscate" code however sometimes all
that can tell you is that "yeah, it's probably malicious".  I would
google for "javascript deobfuscate".

You could submit the blogspot site to an online sandbox for
analysis, like I just did:

and possibly find other URLs found in the de-obfuscated code to see
what they do.... like this one

... I've yet to find a .cn domain name I could trust.  LOL.

Follow down the rabbit hole...

That way you can find out if the PC was infected, and how to clean
it up.

Otherwise it would seem like some sort of facebook worm that spreads
using the FB address book.  Was the user logged into Facebook at the
time?  Might be a good idea to change their password, sounds like it
either used the active facebook session to send itself out, or maybe
a cookie with the user's saved credentials.


From: chris.blazek at
Date: Tue, 1 Dec 2009 14:54:36 -0600
To: pauldotcom at
Subject: [Pauldotcom] phishing question

A coworker clicked on a link in an email and was directed to
facebook then redirected to the following site:
despatiesmercemerce . blogspot . com
All of there fb contacts then received the same email. I pulled up
the site in malzilla and noticed a script block in the header that
looks like it's obfuscated.

I was wondering if someone in the group could figure out what the
site was trying to do.


Pauldotcom mailing list
Pauldotcom at
Main Web Site:
Pauldotcom mailing list
Pauldotcom at
Main Web Site:
Pauldotcom mailing list
Pauldotcom at
Main Web Site:

Current thread: