Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 27th, 2004, 05:37 AM
Laurie
 
Posts: n/a
Default "Padonak./fa/hta.php/object.cfm"

Anyone else heard of this "object" or been attacked while on a forums website?

This hit a game website I help admin December 22nd. I have tried looking up any information about who or where it came from but to no avail.

One of the moderators found out this was a malicious program that uses a redirect exploit through IFRAME. Tries to open a couple of .htm files from "padonak.info" (IP 211.115.110.230)
it uses IFRAME again to download the "proc.jarjava, archive and run MainApp.class. This in turns loads other classes which contain JavaByteVerify exploit.

It will also allow a Bloodworm exploit.6 installed through "padonak.info/fa/hta.php/object.cfm object". Anytime anyone goes there, this gets installed and appears on the taskbar. If clicked on, it disables the ActivX so the pages will not appear properly. Those with good anti virus programs can get rid of it easily enough. However, it seems to be able to get around routers and even firewalls like Black Ice.

With me, this "object" allowed a suspicious "ANYUMR.DLL" to be installed in my Windows System folder. I ran an online Malware scan and it was a Trojan.Proxy.69 (Dr. Web) or a Trojan.Win32.Pakes ( Kaspersky Anti-Virus) depending on which program named it. The packer is UPX. Some kind of backdoor Trojan. And because it is a trojan, why virus scanners may not pick it up.

I am sure it is "very helpful" installing/allowing other junk in as well if you are not behind a good firewall/anti virus program to catch and quarantine it.

I was able to get rid of it after scanning with HijackThis, renaming it while in SafeMode, deleting all files in my TEMP folder (it installs alot of malware junk there) and so on. Easy enough but annoying as my AVG Free 7 did not see it and some game community members even had problems with theirs. If you are not using Internet Explorer browser, the object will not install on the taskbar.

Now it has changed where it will appear if so many "GETs" are done on the website forums before appearing. Usually after 6 or 10. As admin of that site, this is extremely annoying while running the forums.

I have contacted the company that controls the website as soon as it happened December 22. But being Christmass Holidays, I expect nothing will be done until this coming week after everyone gets back.
  #2  
Old December 29th, 2004, 05:47 AM
Laurie
 
Posts: n/a
Default Re: "Padonak./fa/hta.php/object.cfm"

Update

One of my moderators identified what the hackers used to attack our forums website. It was done by "Xpire/SplitInfinity Exploit" using "Suckit toolkit" Information can be found Vital Security.Org

As for the Padonak.info:


CAUTION!!! Only click the following links if you are NOT using Internet Explorer

Check out http://<remove>/x.htm and http://<remove>x1.htm

These are the *.htm files using the IFRAME exploit. The trojan/virus that has infected the website is changing the "GET" requests after clicking anywhere from five to ten links that use PHP. This includes the main page and our editing website
----------------------------

No links to malware please Laurie--Ron

Last edited by ronjor : December 29th, 2004 at 09:21 AM. Reason: Remove links
  #4  
Old January 3rd, 2005, 04:55 AM
Laurie
 
Posts: n/a
Default Re: "Padonak./fa/hta.php/object.cfm"

My apologies for overstepping, Ron.
  #5  
Old January 3rd, 2005, 05:00 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: "Padonak./fa/hta.php/object.cfm"

Quote:
Originally Posted by Laurie
My apologies for overstepping, Ron.
That's ok Laurie, we just want to keep everyone safe

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #6  
Old January 15th, 2005, 02:26 AM
Laurie
 
Posts: n/a
Default Re: "Padonak./fa/hta.php/object.cfm"

Update

A few days ago, our problem was finally solved by our new server hosts techsupport. New and updated forums were installed as well. Still some tweaking needs to be done but at least the "padonak.info" is gone finally.

All those who sent out those sneaky worms, over the holidays, really need to be drawn and quartered.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:28 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums