LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-04-2015, 07:30 PM   #1
Sefyir
Member
 
Registered: Mar 2015
Distribution: Linux Mint
Posts: 634

Rep: Reputation: 316Reputation: 316Reputation: 316Reputation: 316
Email .js virus


I got a "E-fax" with a attachment of document000262537.doc.js (Red flag)
I stringed the file and it looks like it's "camouflaged" with chunks of code wrapped into variables which are then used to group together into the (probably) malicious code and run.

Eg.
Code:
var g4=' { }'
var v0='= w'
var u4='{ fo'
var k7='WScr'
var r2='rket'
var d7=' {'
var d6='Creat'
var r5='nd('
var h2='tr+'
...
a9=p5
i5+=a9
a9=e0
i5+=a9
a9=y6
i5+=a9
a9=f3
i5+=a9
a9=t2
i5+=a9
a9=q9
i5+=a9
Pastebins:
Original
; changed to newlines (\r)

I didn't run it, but I'm curious what the constructed code does. Whether linux or windows based..
I searched some parts of the code but nothing came up.
Would it be worth reporting and who would I report it to?

Last edited by Sefyir; 12-06-2015 at 08:48 AM.
 
Old 12-05-2015, 03:23 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Just run the original through one of the aggregating virus scanners will you?
 
Old 12-05-2015, 03:23 AM   #3
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by Sefyir View Post
; changed to newlines (\r)

I didn't run it, but I'm curious what the constructed code does.
from what i can see it is safe to replace the last line: "p8()(i5);"with the .js equivalent of "echo "$i5"", and see what the resulting code looks like.
 
Old 12-05-2015, 08:27 PM   #4
Sefyir
Member
 
Registered: Mar 2015
Distribution: Linux Mint
Posts: 634

Original Poster
Rep: Reputation: 316Reputation: 316Reputation: 316Reputation: 316
Quote:
Originally Posted by unSpawn View Post
Just run the original through one of the aggregating virus scanners will you?
I ddg'd "aggregating virus scanners" and got virustotal

https://www.virustotal.com/en/file/4...is/1449368248/

Quote:
from what i can see it is safe to replace the last line: "p8()(i5);"with the .js equivalent of "echo "$i5"", and see what the resulting code looks like.
I don't know js, but I think you're right.
 
Old 12-06-2015, 05:05 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
So it's Nemucod, a downloader. Microsoft-only. Case closed?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about possible email virus, but possibly not... BallsOfSteel General 8 07-25-2008 03:37 PM
Email anti-virus problem Wynand1 Linux - Security 1 09-19-2004 10:16 PM
RE: Email Anti-virus parttimenerd Linux - Software 1 09-04-2004 10:36 PM
Treatment of virus in email attachment royschnettler Linux - Newbie 6 08-07-2004 04:33 AM
Email virus protection software? defa0009 Linux - Security 9 06-19-2003 05:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration