top_left top_right
bottom_left
Next Event: Unknown | Forum Rules | QGL Website | Event Registration
openFolder AusForums.com
iconwatfolderLineopenFolder LANs
iconwatfolderLineopenFolder QGL
iconwatfolderLineopenFolder QGL Forum
Author
Topic: Chilli Willies trojan?
thermite
Posts: 2262
Location: Brisbane, Queensland
Anyone else get a trojan warning when they google "Chilli Willies"

Here is the link but don't click on it without Avast!
Spoiler:
http://www.google.com.au/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-GB%3Aofficial&hs=nyq&q=chilli+willies&btnG=Search&meta=


system
--
Zylox
Posts: 1045
Location: Brisbane, Queensland
damn lucky i had avast on.
i dont think its safe to link like that man.

DONT CLICK WITHOUT ANTIVIRUS!
trog
AGN Admin
Posts: 27537
Location: Brisbane, Queensland

You get a trojan warning when you just google that thing? What AV are you using? What browser/OS?
Zylox
Posts: 1046
Location: Brisbane, Queensland
yeah just from googling
pARODY
Posts: 359
Location: Brisbane, Queensland
any details on the warning you got?
thermite
Posts: 2263
Location: Brisbane, Queensland
avast! here
if this is a false positive I would be so pissed if I was the Chilli Willies man. (assuming there is such a man)
If this is their fault it brings new meaning to their slogan "Be WARNED I may BITE back!".
pARODY
Posts: 360
Location: Brisbane, Queensland
You can get potential warnings from javascript in a link on the site. I also see there is a youtube preview linked on that page when I load it. There are a number of flash/SWF exploits rolling around at the moment, but I've not seen them come from youtube (which is where that video is from).
Zylox
Posts: 1047
Location: Brisbane, Queensland
Js: Cruiser-B [Trj]
Trojan
thermite
Posts: 2264
Location: Brisbane, Queensland
A trojan horse was found, yadda yadda yadda

Filename: http://www.chilliwillies.com.au/
Malware name: JS:Cruzer-B [Trj]
Malware type: Trojan Horse
VPS version: 090804-0, 04/08/2009
pARODY
Posts: 361
Location: Brisbane, Queensland
Ok, its been compromised.

Looking into it now.

wget the front page and after a chunk of whitespace is some appended javascript.

Nice catch Avast! :P
BillyHardball
Posts: 9537
Location: Brisbane, Queensland
Why would you google Chilli Willies? Is that some sort of gay restaurant or something?
trog
AGN Admin
Posts: 27538
Location: Brisbane, Queensland

Ok, its been compromised.

Looking into it now.

wget the front page and after a chunk of whitespace is some appended javascript.

Nice catch Avast! :P
weird, I don't see that after going to the page and saving it out as .html (from firefox)

lemme know if I need to start panicking
thermite
Posts: 2265
Location: Brisbane, Queensland
Chilli Willies? Is that some sort of gay restaurant or something?

Why don't you look at the site and find out? :D

It's an australian company that makes chilli sauces, I was just enjoying splashing some on my kebab right now and thought I'd look up their site.
Zylox
Posts: 1049
Location: Brisbane, Queensland
Ahh, yes I have their "Calypso Tropical Butt Burner" in the cupboard. Got it at the Chop Shop in the Coco's complex @ Annerley about 3 years ago.
pARODY
Posts: 362
Location: Brisbane, Queensland
The html file when I viewed it in hex has the whitespace filled with %0a%0d which is /r/n. So your normal viewer may not load it correctly. I used Wget on a linux box and then just cat the index.html and see the script.
vbcoder
Posts: 158
Location: Townsville, Queensland
i clicked it and no virus warning

i dont have antivirus either
trog
AGN Admin
Posts: 27539
Location: Brisbane, Queensland

The html file when I viewed it in hex has the whitespace filled with %0a%0d which is /r/n. So your normal viewer may not load it correctly. I used Wget on a linux box and then just cat the index.html and see the script.
yeh wget was the first thing I tried, except weirdly (in windows anyway) wget'ing that URL gives me a 403 error.
thermite
Posts: 2266
Location: Brisbane, Queensland
funny story, reading the above post I didn't know you could wget in windows, so I googled wget in windows and on the first page is trog's website.
lewd
Posts: 175
Location: Brisbane, Queensland
i googled 'chilli willies'. there website was at the top of the search results. i clicked the link, went to there site........what next?
Clubby
Posts: 230
Location: Brisbane, Queensland
enter your credit card details :)
Spook
Posts: 25824
Location: Brisbane, Queensland
hot ranga > chilli willies
pARODY
Posts: 363
Location: Brisbane, Queensland
Just finished decoding the javascript, and the link it went to is now dead. :(

It was redirecting to a dynamic downloader on http://www.google analitics ">.net/__utb.js?"+document.reerrer+"\"> but was broken in the script :]

[parody@vps ~]$ wget "http://www.google analitics .net/__utb.js" -U="Internet Explorer 6.0"
--16:35:57-- http://www.google analitics .net/__utb.js
Resolving www.google analitics .net... 85.249.131.46
Connecting to www.google analitics .net|85.249.131.46|:80...
and that connection times out.

My personal shell has the IP cached. My work threatbox doesn't :(

parody@threatbox:~$ nslookup www.google analitics .net
Server: 4.2.2.1
Address: 4.2.2.1#53

Non-authoritative answer:
Name: www.google analitics .net
Address: 127.0.0.1

parody@threatbox:~$

If I wasn't so busy I could have caught the binary :( oh well.
pARODY
Posts: 364
Location: Brisbane, Queensland
Took too long to rebuild my spidermonkey install. Makes processing javascript so easy but new threatbox didn't have it installed. Very handy tool if you're into malware analysis. Mine is modded to include handling of document.write, eval() and alert() to external files. It still sucks for recursive code that needs to be decoded to fix the references to defines in the javascript. Have to cut and process in steps to figure that out and then build a big final script to process the lot.

http://blog.didierstevens.com/programs/spidermonkey/ this already has some modifications done to it which I based my further mods from.
thermite
Posts: 2267
Location: Brisbane, Queensland
just gonna write their details here while I've got the sauce bottle with me

Chilli Willies, 4 Cowley Dr, Flinders View, Q, 4305
07 3288 6228, 0419 646 305, info@chilliwillies.com.au

might send an email or something later?

last edited by thermite at 16:56:13 04/Aug/09
pARODY
Posts: 365
Location: Brisbane, Queensland
I've just sent an email to the chilliwillies guys to inform them of the infection. Should hopefully get them fixed up quick. :]
thermite
Posts: 2268
Location: Brisbane, Queensland

Cool, well nerded.
pARODY
Posts: 366
Location: Brisbane, Queensland
Nerding? I do! :]

last edited by pARODY at 17:42:55 04/Aug/09
trog
AGN Admin
Posts: 27540
Location: Brisbane, Queensland

Just finished decoding the javascript, and the link it went to is now dead. :(
Googling tells me its an attack thing that was around last year so I'm guessing its been long gone
pARODY
Posts: 367
Location: Brisbane, Queensland
I just checked our known_malicious list and its a site that has been around since 2002 and changed owners a couple times but always involved in hosting dodgy stuff. Last activity on our list is from February.
HeardY
Gaelic newb
Posts: 16371
Location: Ireland
jesus there is plenty of nerding it up in this thread.

well played old chaps
Fester
Posts: 1
Location: Queensland

Hi Chilli Willies here yes their was a trojan on my web site but this has been removed was a script on the tittle page, not much good all talking about and not telling me??
Fester
Posts: 2
Location: Queensland

Thank you for the was not sure who sent it as I get so much spam
Fester
Posts: 3
Location: Queensland

I have owned Chilli Willies Sauces since 2001 and wonder what is so dogdy about hot sauce?
Fester
Posts: 4
Location: Queensland

Chilli Willies here yes pissed off considering new nothing of the trojan
thermite
Posts: 2420
Location: Brisbane, Queensland
well your poo feels like it's got razor blades in it

anyways I think he meant the website/host was dodgy, not the sauce
Fester
Posts: 5
Location: Queensland

Web Host was Is Melbourne IT when I found out about the Trojan called them they confimed and they removed it for me straight away
system
--
Not a new post since your last visit.
New Post Since your last visit
Back To Forum
Advertise with Us | Privacy Policy | Contact Us
© Copyright 2001-2026 AusGamers Pty Ltd. ACN 093 772 242.
Hosted by Mammoth Networks - Australian VPS Hosting
Web development by Mammoth Media.